Yes, may be there is not any security hole but here is one more reason to set 600 to this file. Any normal admin, for instance I :-), when see tomcat-users.xml first time shall change its permissions and try to submit bug about it. I see now that this is not a grave bug, but I spent my time. :-) People will be more happy with this package if this file will have 600 initially like as another passwords files.
--
Olleg Samoylov

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature



Reply via email to