tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Eric B." <>
Subject Re: AJP vs HTTP connectors?
Date Tue, 03 Feb 2009 17:04:33 GMT
"Hassan Schroeder" <> wrote in message
> On Tue, Feb 3, 2009 at 7:38 AM, Eric B. <> wrote:
>> Is there any documentation / howtos available for securely setting up
>> mod_proxy_http and/or mod_proxy_ajp with tomcat?  The little that I
>> know/remember about mod_proxy_http is that if you're not careful, you can
>> end up with some major security holes in your installation.
> Do you have any references to substantiate that?

Offhand, no.  I played with mod_proxy a couple of years ago for some project 
(don't even remember what), and at the time, remember reading that 
incorrectly configuring it could be hazardous.  More specifically than that, 
my memory fails.  It is very possible that whatever security issues there 
were have been resolved.

Unless anyone else has any knowledge about this?



To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message