You can also use request.getSession().invalidate() in order to invalidate the whole session. Both this and the request.logout() (Servlet 3.0 onwards) work irrespective of the auth method.
[Message sent by forum member 'nasradu8']
http://forums.java.net/jive/thread.jspa?messageID=392823