There's a server config option (via soap.xml) to turn off the remote config capability. Production use should obviously use that option ..
The details are explained in the docs. Sanjiva. ----- Original Message ----- From: "Chistian Lacetera" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, December 28, 2001 3:30 PM Subject: Remote Deployng & security problem > I need to protect remote Deploy but there is a problem: > > I can protect (by tomcat) the url name.host:8080/soap/server/rpcrouter > > but this forbid the access to soap clients also. > > I think that isn't the right way but i don't know another. > > I need some suggestion > > Regards > Lacetera Christian.