Hi,

Way back to technic ;-)

When linking apache to tomcats in an untrusted networks, ajp12/ajp13
streams are in clear.

What about crypt stream between apache and tomcat ? Something like
DES with a known key between the two or something like a ticket ?

Actually in my site I could look at everything between APACHE and TC with
a tool like ethereal. 

More we could add mod_jk a list of URLs to encrypt to avoid overload
non sensible URL.
        
What about ?

Reply via email to