Re: Tomcat 3.2.2 beta 4 (insecure default settings)

2001-05-07 Thread Andrey Kartashov
On Mon, May 07, 2001 at 02:11:35PM +0200, GOMEZ Henri wrote: You're right. TC still use ajp12 at its default connector so it listen all interface (which I agree could rise problem). I'm using in my prod systems, ajp13 to connect webservers and ajp12 only for the shutdown purpose (and listen

Re: Tomcat 3.2.2 beta 4 (insecure default settings)

2001-05-05 Thread Andrey Kartashov
On Fri, May 04, 2001 at 07:58:17PM -0400, Andrey Kartashov wrote: [skpd] Let's be prudent here. The standard configuration must avoid security hole. Many users will have tomcat in front and we must avoid someone outside shutdown their TC boxes. Let me clarify this:) I don't ask you