Dear Petr,

any comment on this subject? The question is related to OpenSolaris package
(*) where we have all files owned by root and tomcat is executed with
dedicated user credentials.

Currently tomcat-user.xml and conf directory is owned by tomcat user but it
makes some noise in our package auditing.

The question is what is limitation of setting user database as readonly (in server.xml) for Tomcat 6.0.18 and having tomcat-user.xml and conf directory
owned by root.


Does tomcat-users.xml ever have to be written from Tomcat? I routinely run with tomcat-users.xml as read-only and it is no problem for me. I don't actually use that mechanism at all.
--
Kees Jan

http://java-monitor.com/forum/
kjkos...@kjkoster.org
06-51838192

Human beings make life so interesting. Do you know that in a universe so full of wonders, they have managed to invent boredom. Quite astonishing... -- Terry Pratchett


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to