You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@tomcat.apache.org by Lior Shliechkorn <li...@yahoo.com> on 2003/05/24 06:18:52 UTC

Question: Tomcat Security Handbook

Hello,
 
I'm reading the "Apache Tomcat Security Handbook" (ISBN 1-86100-830-9...if you're interested in looking to get it). I'm running Tomcat 4.0.5, which I will shortly upgrade to 4.1.18) on Windows 2000. For security purposes, it is recommended to create a "Tomcat" account that has very limited permissions and that runs Tomcat as a service.
 
My question is whether I need to run Tomcat as a service once I create this tomcat account? Can I still run Tomcat as Standalone? What is the benefit/drawback of running Tomcat as a service?
 
Thanks,
Lior


---------------------------------
Do you Yahoo!?
The New Yahoo! Search - Faster. Easier. Bingo.

Re: Question: Tomcat Security Handbook

Posted by Bill Barker <wb...@wilshire.com>.
On a Windows box, the main advantage to running as a Service is that Tomcat
will start up every time that the machine is re-booted.  If you don't care
if your IT staff calls you up at 3AM to tell you that they just re-booted
the machine, can you please drive down and startup Tomcat for us?,  then no
problem ;-).

"Lior Shliechkorn" <li...@yahoo.com> wrote in message
news:20030524041852.16346.qmail@web40707.mail.yahoo.com...
> Hello,
>
> I'm reading the "Apache Tomcat Security Handbook" (ISBN 1-86100-830-9...if
you're interested in looking to get it). I'm running Tomcat 4.0.5, which I
will shortly upgrade to 4.1.18) on Windows 2000. For security purposes, it
is recommended to create a "Tomcat" account that has very limited
permissions and that runs Tomcat as a service.
>
> My question is whether I need to run Tomcat as a service once I create
this tomcat account? Can I still run Tomcat as Standalone? What is the
benefit/drawback of running Tomcat as a service?
>
> Thanks,
> Lior
>
>
> ---------------------------------
> Do you Yahoo!?
> The New Yahoo! Search - Faster. Easier. Bingo.




---------------------------------------------------------------------
To unsubscribe, e-mail: tomcat-user-unsubscribe@jakarta.apache.org
For additional commands, e-mail: tomcat-user-help@jakarta.apache.org