Permissions of tomcat-users.xml

Michael Koch konqueror at gmx.de
Thu Jul 26 12:06:33 UTC 2007


On Thu, Jul 26, 2007 at 01:46:18PM +0200, Marc wrote:
> Hi there,
> 
> I noticed that, on a standard installation of tomcat5.5 on Debian/etch
> (last checked with 5.5.20-2), /var/lib/tomcat5.5/conf/tomcat-users.xml
> is world-readable (644). I think that's a security problem and tomcat
> seems to work fine when the file is chmodded to 400.
> 
> Should I file a bug report on this?

Yes, please file a bug report for this issue. This make it easier to
track this.


Cheers,
Michael
-- 
 .''`.  | Michael Koch <konqueror at gmx.de>
: :' :  | Free Java Developer <http://www.classpath.org>
`. `'   |
  `-    | 1024D/BAC5 4B28 D436 95E6 F2E0 BD11 5923 A008 2763 483B



More information about the pkg-java-maintainers mailing list