WebApp Sec mailing list archives

RE: Tomcat on port 80 or Java as root


From: "Harshul Nayak" <harshul.nayak () patni com>
Date: Fri, 12 Mar 2004 12:44:47 +0530

Hi raj
AFAIK tomcat is a servlet container running on apache.
well... apache webserver should never be run as "root" for various security
reasons.

not sure regs tux !
-regs
Harshul

-----Original Message-----
From: Rajkumar S [mailto:listuser () myrealbox com]
Sent: Thursday, March 11, 2004 9:13 PM
To: webappsec () securityfocus com
Subject: Tomcat on port 80 or Java as root


Hi,

What are the implications of running tomcat as root(ie to run tomcat on
port 80) Is java secure enough to run as root, or should I run some
thing like apache in front ?

How about having Tux as a front end? Is it advisable from a security
point of view?

with warm regards,

raj


Current thread: