...
[13:52:24 CDT(-0500)] <serac> But you mapped /*.cfm to tomcat.
[13:53:47 CDT(-0500)] <atilling> that was the point having apache protect certain folders but have the app still mapped to tomcat
[13:54:14 CDT(-0500)] <serac> I'm thinking that mapping is too broad.
[13:54:42 CDT(-0500)] <atilling> we have hundreds of *.cfm files, we only want the ones under a particular folder to be secure