In apache-tomee-webprofile-1.5.0/conf/tomcat-users.xml, the following users are defined:
<role rolename="tomee-admin"/> <user password="tomee" roles="tomee-admin,manager-gui" username="tomee"/> Wouldn't it be better to have those commented out by default? -- View this message in context: http://openejb.979440.n4.nabble.com/v1-5-0-Security-concern-tp4657814.html Sent from the OpenEJB User mailing list archive at Nabble.com.
