    Authentication cache timeout vs. flushing

    sbotten


      Are there any drawbacks to setting the DefaultCacheTimeout attribute to a low value (e.g. 30 secs instead of the hardcoded default 30 minutes), compared to doing an explicit flush() only when required? (Users changing their own password is not an issue here.) I'm using JBoss 3.2.1.