Just a thought, but what does your login-config.xml file look like?
If you had two LDAP login-modules defined for your application policy, with the first one
flagged as "sufficient", then this behavior you describe would make sense. There
would be two failed logins and only one successful one and both failed logins would result
in very similar network traffic.
EG
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4134255#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...