Yes, may be there is not any security hole but here is one more reason
to set 600 to this file. Any normal admin, for instance I :-), when see
tomcat-users.xml first time shall change its permissions and try to
submit bug about it. I see now that this is not a grave bug, but I spent
my time. :-) People will be more happy with this package if this file
will have 600 initially like as another passwords files.
--
Olleg Samoylov
smime.p7s
Description: S/MIME Cryptographic Signature