Wednesday, April 01, 2009

Tomcat security

One painful thing I'm learning is the restrictions tomcat has when running under the -security option.Basically many things (eg: jaxb, jax-ws, axis) can't run.
Locating the appropriate permissions is pretty daunting.Now l has a tool calledProfilingSecurityManager (which is just a custom SecurityManager class) which displays the permissions required(basically start catalina with then use a perl script
Another reference is
Basically export,failurethen run run -security
Look in catalina.out for denied.Then seek for "domain that failed ProtectionDomain" for the codebase or domain. also allows you to do the same for standard java execution.

No comments: