[Tomcat9][Linux]listening all local addresses by default is not security best practice

2022-11-23 Thread tommydu1123
Hi there, The default behaviour of http connector is listenning all interfaces. It is found in the description of "address" in attributes section. (https://tomcat.apache.org/tomcat-9.0-doc/config/http.html#SSL_Support) In terms of security default, it could be not best practice. In case of

listening all local addresses by default is not security best practice

2022-11-23 Thread tommydu1123
Hi there, Product: Ant Apache httpd-2 Apache httpd-test APR POI Rivet Taglibs Tomcat 10 Tomcat 8 Tomcat 9 Tomcat Connectors Tomcat Modules Tomcat Native WebSH