From users-return-264045-archive-asf-public=cust-asf.ponee.io@tomcat.apache.org Fri Mar 2 17:54:52 2018 Return-Path: X-Original-To: archive-asf-public@cust-asf.ponee.io Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx-eu-01.ponee.io (Postfix) with SMTP id B956F18062F for ; Fri, 2 Mar 2018 17:54:51 +0100 (CET) Received: (qmail 86414 invoked by uid 500); 2 Mar 2018 16:54:49 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 86403 invoked by uid 99); 2 Mar 2018 16:54:49 -0000 Received: from mail-relay.apache.org (HELO mailrelay2-lw-us.apache.org) (207.244.88.137) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 02 Mar 2018 16:54:49 +0000 Received: from Christophers-MacBook-Pro.local (pool-173-66-117-24.washdc.fios.verizon.net [173.66.117.24]) by mailrelay2-lw-us.apache.org (ASF Mail Server at mailrelay2-lw-us.apache.org) with ESMTPSA id E0E3CE02 for ; Fri, 2 Mar 2018 16:54:48 +0000 (UTC) Subject: Re: tomcat 8.5.28 To: users@tomcat.apache.org References: <004101d3b22f$eebfca70$cc3f5f50$@philasd.org> <28DE18D2F5278947A1FC6B3DED0C695F6D49A609@MISOUT7MSGUSRCB.ITServices.sbc.com> <005401d3b231$e21c6650$a65532f0$@philasd.org> <45d9e878-c5c1-7555-5fe3-94f4263c49f7@olafkock.de> From: Christopher Schultz Message-ID: <96711a99-db6d-7826-1178-1ac97d637966@christopherschultz.net> Date: Fri, 2 Mar 2018 11:54:48 -0500 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.6.0 MIME-Version: 1.0 In-Reply-To: <45d9e878-c5c1-7555-5fe3-94f4263c49f7@olafkock.de> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Olaf, On 3/2/18 9:30 AM, Olaf Kock wrote: > On 02.03.2018 15:22, Cheltenham, Chris wrote: >> From: Cheltenham, Chris [mailto:ccheltenham-ext@philasd.org] >> Sent: Friday, March 02, 2018 9:08 AM To: 'Tomcat Users List' >> Subject: tomcat 8.5.28 >> >> Hello, >> >> Has anyone set up tomcat as a non-root use? >> >> I have set it up successfully however, I have to bound the >> non-root user to port 8443. >> >> What is the best way to reroute 8443 through 443? There are >> several options. Everything is set up at send to port 443 so I >> need to reroute 8443 in and out of 443 >> >> CentOS 7 by the way - > "what is the best (TM)?" -> "It depends" > > Tomcat runs well on unprivileged ports, and depending on your OS, > familiarity with configuring it, other infrastructure etc, you > have different options. Are you familiar with them - as you mention > that there are many? > > You can * use iptables redirection, * have a > proxy/webserver/loadbalancer in front, * enable unprivileged > binding to the port You can also use jsvc which can: * bind to privileged ports, then drop privileges * monitor and restart dead Tomcat processes * send a signal to rotate logs (like stdout!) I use a reverse-proxy for everything (and I'd recommend that everyone doing anything in the "real world" do the same), so I don't need such things, but I think I'd probably want to use jsvc for this purpose because it's fairly self-contained PLUS you get the auto-restart capabilities should you want them. > As we were discussing documentation in another thread these days: > I've expected to find a solution to your question in the FAQ and > wanted to link to it - but didn't find any entry there. There's a > patch to go on my list, with no ETA though. Maybe a side-task > during that Manchester Tomcat training. It's in the Wiki, not the user's guide: https://wiki.apache.org/tomcat/HowTo#How_to_run_Tomcat_without_root_priv ileges.3F It doesn't even come up in Google, so it's no wonder that nobody can find it. We should probably roll some of this stuff into the user's guide so it's in a better place. The Wiki is ... not a great place to put things IMO. - -chris -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAlqZgdgACgkQHPApP6U8 pFiGERAAoE7DTJUDhCMMTVT12j1tR5TS/0+TDltXlaT/CWFJ1ulCv2l8Oix4A7RH oFALw0gYjZg9/WPZd73CEtN5dfKHSffll18mJcSIpaJ2uf2sx+nbcqMpGOxrkQ5x osM9Vj/X7QTAXfBABwffAzw12kw5QpfwdxfapQS9KkK2U4gvtIB1oo1WCBL+yziA rKA3mA6IBKIGWk8u9BhbHJeTnmL4mPaIZqLep+M5CgOykfAu7TYdvMViovOxWCTv o5kB6xsuhZ88zdmkGJ2BGFokl0UzKtcYic3IN/s4KqcU2fM+2UJrSSHocpxW3Nfw ppmHGp4XaKW6oAFu4VjDDnWjnP6nDs5lH1VLmIySDm8B7nXpqbC7ML/rBde1VFMZ jVbUojbxJ+jIpXs6jg6nxTCRh/PssvWEQ/3e0Ank+xfJ3s4ay+kXYlP8M4IL8VFV M8tsXY8pAmknh9BnGV2fz0R49+Ir8aJEBRrYm1TLKnC8L9O/hqqlOEftqikYajvD qJlYKCmeZfDYdFkKR1TcgcC1kOpZkgdkSCc77NEBM0+y5ln/shDUCX5MkxrHe/zE leqntUfdWVhsfeG84MR5zmFbcWcNYNVov6A/7cW6Sb5Rlv7PWIcruyTgTEIotqwd DPFNk54910K3yy4UAyDgBgkiZTqz8k2eWx4W7FGaaMD2c9xCq50= =9WCp -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org