tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Charlie C.L. King" <>
Subject Re: Securing Manager Role
Date Wed, 26 Oct 2005 07:57:46 GMT
you can change it to a digested form, either in md5 or in sha1 or some
others(see but sha1 should be safer. here's
the choir you have to do.

1. in your server.xml, add to its child element <Realm> a new attribute
named "digest" and with its value "SHA1"(whatever you want).

2. run this

% java -classpath $CATALINA_HOME/server/lib/catalina.jar:/path/to/commons-
logging.jar org.apache.catalina.realm.RealmBase -a sha1 <cleartext_password>

you'll get the digested passphrase

3. use the digested passphrase as password in you tomcat-user.xml

4. be sure to restart tomcat and then you can try it

the way digest means it should be difficult *BUT NOT IMPOSSIBLE* to decrypt
in case anyone might be able to read that file, thus you should secure the
user file and prevent others from reading it.

Regards, Charlie
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message