WebApp Sec mailing list archives

RE: Tomcat on port 80 or Java as root


From: "urgoez" <urgoez () yahoo Fr>
Date: Thu, 11 Mar 2004 19:27:32 +0100

From a security point of view, any front end should run as root.
You have to define a chrooted environment.
The question is not to know if java is secure enough today but if a new
vulnerability could be discovered and exploited tomorrow. I think the answer
is yes. 

Regards,
urgoez

Hi,

What are the implications of running tomcat as root(ie to run tomcat on 
port 80) Is java secure enough to run as root, or should I run some 
thing like apache in front ?

How about having Tux as a front end? Is it advisable from a security 
point of view?

with warm regards,

raj


Current thread: