> From: Tk, Pramod (NSN - IN/Bangalore) [mailto:pramod...@nsn.com]
> Subject: Query on Tomcat Server.xml
> 
> I presume this type of hardcoding in server.xml is security loop hole.

Not really.

If you don't put the password in server.xml, where are you going to put it?  
The server.xml file can have the same access constraints applied to it as any 
other location for the password.

 - Chuck


THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY 
MATERIAL and is thus for use only by the intended recipient. If you received 
this in error, please contact the sender and delete the e-mail and its 
attachments from all computers.


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to