"Hassan Schroeder" <hassan.schroe...@gmail.com> wrote in message news:4eedb92a0902030808n399c1107x90207c3edb9d9...@mail.gmail.com... > On Tue, Feb 3, 2009 at 7:38 AM, Eric B. <ebe...@hotmail.com> wrote: > >> Is there any documentation / howtos available for securely setting up >> mod_proxy_http and/or mod_proxy_ajp with tomcat? The little that I >> know/remember about mod_proxy_http is that if you're not careful, you can >> end up with some major security holes in your installation. > > Do you have any references to substantiate that?
Offhand, no. I played with mod_proxy a couple of years ago for some project (don't even remember what), and at the time, remember reading that incorrectly configuring it could be hazardous. More specifically than that, my memory fails. It is very possible that whatever security issues there were have been resolved. Unless anyone else has any knowledge about this? Thanks, Eric --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org