Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-17 Thread Sean Davis
On Mon, Aug 17, 2009 at 9:40 AM, Trevor wrote: > > How would this be done? Don't you need root permission to install the WAR > into $CATALINA_HOME/webapps ? > Ah ... I'm guessing you can "deploy" XWiki through Tomcat's management app? > Is this what you mean? > Not all tomcat installations are

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-17 Thread Sergiu Dumitriu
Trevor wrote: >> No idea what you call location. Location doesn't matter in general and > > By "location" I was referring to what the directory is called that xwiki is > installed into (eg. "xwiki" or "xwikifarm"). It should work out-of-the-box without any problems. I did deploy XWiki to o

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-17 Thread Vincent Massol
On Aug 17, 2009, at 3:40 PM, Trevor wrote: > Thanks, Vincent, for your replies. > > On Sat, 15 Aug 2009 10:19:54 +0200 Vincent Massol > wrote: > >> From a user POV only groovy scripting can access files on the >> filtesystem and do dangerous things. This is why we have a special >> right calle

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-17 Thread Trevor
Martin, thanks for your reply, and for the SSL how-to link, I appreciate it. I have come across a document which is quite useful, specfically about Securing Tomcat: http://www.owasp.org/index.php/Securing_tomcat I found it here: https://help.ubuntu.com/community/ApacheTomcat5 Trevor ___

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-17 Thread Trevor
Thanks, Vincent, for your replies. On Sat, 15 Aug 2009 10:19:54 +0200 Vincent Massol wrote: > From a user POV only groovy scripting can access files on the > filtesystem and do dangerous things. This is why we have a special > right called programming right that is required for groovy scrip

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-15 Thread Vincent Massol
On Aug 15, 2009, at 8:48 AM, [Ricardo Rodriguez] Your EPEC Network ICT Team wrote: > Hi, > > Trevor wrote: >> Hello, >> >> 1. I am wondering if any users running XWiki on Tomcat 5.5 have set >> up a SecurityManager policy. The documentation isn't really clear >> on this, other than "it's a

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-15 Thread Martijn.Ras
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Heya Trevor, 1 Have not yet looked into SecurityManager. As i'm running XWiki on a dedicated server, i'm not really concerned about tomcat accessing files on the local file system. Any connecting to a host other than the one the applet was loaded

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-15 Thread Vincent Massol
Hi Trevor, On Aug 15, 2009, at 2:34 AM, Trevor wrote: > Hello, > > 1. I am wondering if any users running XWiki on Tomcat 5.5 have set > up a SecurityManager policy. The documentation isn't really clear > on this, other than "it's an issue" that may not be resolved. The > one "comment" on

Re: [xwiki-users] XWiki (with Tomcat/MySQL) security

2009-08-14 Thread [Ricardo Rodriguez] Your EPEC Network ICT Team
Hi, Trevor wrote: > Hello, > > 1. I am wondering if any users running XWiki on Tomcat 5.5 have set up a > SecurityManager policy. The documentation isn't really clear on this, other > than "it's an issue" that may not be resolved. The one "comment" on > XWiki.org that has a security policy is