Hi all, I am really not sure if this topic goes in this list but MAy BE somebody could give a hint on about where to look into.
We have apache with proxy resolving tomcat 8 server cas application against cas 3.4 server with trusted authentication.
When resolving urls after login we can see that protocol is alternatively https and http when loading url resources.
This should not bother at all IF we didnt require https as expressed in hhtp in spings-security s entry configuration.
This happens in production environmet (apache in frotn). testing with only tomcat is working ok!!!
Would really appreciate any help on this!
Thank you Manfredo Hopp