Hi, David, I'm not a security expert, but it sounds to me like your port
scanner hit the Tomcat shutdown port. Here's an article on hardening
Apache Tomcat:

http://www.mulesoft.com/improving-apache-tomcat-security-step-step-guide


It's perfectly fine to set the Tomcat shutdown port to -1, which disables
that feature. However...

I personally prefer to run Tomcat behind regular Apache [1], and reverse
proxy just the ports I'm interested in exposing (that's usually just 8009,
the AJP-proxy port). Then Tomcat can do its thing, and Apache can handle
the public.

[1] 
https://wiki.duraspace.org/display/DSPACE/DspaceOnStandardPorts#DspaceOnSta
ndardPorts-Method2a-UseApacheHTTPD(mod_proxy_ajp)+Tomcat(port8009)
--
HARDY POTTINGER <[email protected]>
University of Missouri Library Systems
http://lso.umsystem.edu/~pottingerhj/
https://MOspace.umsystem.edu/
"It is a well-known fact in any organization that, if you want a job done,
you should give it to someone who is already very busy." --Terry
Pratchett, Unseen Academicals





On 11/15/13 8:48 AM, "Schuster, David" <[email protected]> wrote:

>This may not be a Dspace issue, but hopefully someone can point me in the
>right direction.  During a port scan of our Dspace instance before we
>make it public Apache/Tomcat shutsdown.
> 
>Being fairly new to tomcat ­ where might I look and in which log to
>determine why this is happening?  I am open to suggestions as to how to
>fix it as well!
> 
>David Schuster
>Texas Woman's University
>Director of Library Information Technology & Technical Support
>PO Box 425528
>Denton TX 76204-5528
> 
>Phone: 940-898-3909
>Fax: 940-898-3764
> 
>[email protected]
> 
>


------------------------------------------------------------------------------
DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps
OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access
Free app hosting. Or install the open source package on any LAMP server.
Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native!
http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk
_______________________________________________
DSpace-tech mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/dspace-tech
List Etiquette: https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

Reply via email to