Thanks for your reply Tim. I changed the xhtml to jsf, but unfortunately the same problem occurs. Also I think that I should point out that the application I am working on, all the URLs that are sent by the client end with xhtml. Not entirely sure why that is, but it renders the pages correctly, including all of the jsf processed tags. On the other hand, if the pages are requested ending with jsf, the resources (css, images, javascript) produce 404 errors. In both cases, if I attempt to access restricted pages it correctly redirects to the signin page, unless the current session already has an authorized principal, which is then correctly allowing access to the page. As for the URLs ending with xhtml, that is not specified, instead only the view Id is provided, for example: