Skip to Content.
Sympa Menu

grouper-users - [grouper-users] remove DOCROOT from grouper tier package

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] remove DOCROOT from grouper tier package


Chronological Thread 
  • From: "Hyzer, Chris" <>
  • To: " Mailing List" <>
  • Subject: [grouper-users] remove DOCROOT from grouper tier package
  • Date: Tue, 14 May 2019 19:49:48 +0000

The ROOT dir is currently in the Grouper TIER container for tomcat and tomee.  These things are typically removed.

 

https://tomcat.apache.org/tomcat-7.0-doc/security-howto.html#ROOT

 

"The ROOT web application presents a very low security risk but it does include the version of Tomcat that is being used. The ROOT web application should normally be removed from a publicly accessible Tomcat instance, not for security reasons, but so that a more appropriate default page is shown to users."

 

This was discussed on the slack channel and the consensus for 2.4 is to remove ROOT and put a redirect in apache so that / goes to /grouper/

 

Anyone disagree?

 

Thanks

Chris



  • [grouper-users] remove DOCROOT from grouper tier package, Hyzer, Chris, 05/14/2019

Archive powered by MHonArc 2.6.19.

Top of Page