Author: kkolinko Date: Sun Dec 25 13:33:20 2011 New Revision: 1224608 URL: http://svn.apache.org/viewvc?rev=1224608&view=rev Log: Merged revision 1224607 from tomcat/trunk: Improve manager-howto.xml: Document the list of roles that allow access to Manager webapp. The manager-script role is just one of them.
Modified: tomcat/tc7.0.x/trunk/ (props changed) tomcat/tc7.0.x/trunk/webapps/docs/manager-howto.xml Propchange: tomcat/tc7.0.x/trunk/ ------------------------------------------------------------------------------ --- svn:mergeinfo (original) +++ svn:mergeinfo Sun Dec 25 13:33:20 2011 @@ -1 +1 @@ -/tomcat/trunk:1156115,1156171,1156276,1156304,1156519,1156530,1156602,1157015,1157018,1157151,1157198,1157204,1157810,1157832,1157834,1157847,1157908,1157939,1158155,1158160,1158176,1158195,1158198-1158199,1158227,1158331,1158334-1158335,1158426,1160347,1160592,1160611,1160619,1160626,1160639,1160652,1160720-1160721,1160772,1160774,1160776,1161303,1161310,1161322,1161339,1161486,1161540,1161549,1161584,1162082,1162149,1162169,1162721,1162769,1162836,1162932,1163630,1164419,1164438,1164469,1164480,1164567,1165234,1165247-1165248,1165253,1165273,1165282,1165309,1165331,1165338,1165347,1165360-1165361,1165367-1165368,1165602,1165608,1165677,1165693,1165721,1165723,1165728,1165730,1165738,1165746,1165765,1165777,1165918,1165921,1166077,1166150-1166151,1166290,1166366,1166620,1166686,1166693,1166752,1166757,1167368,1167394,1169447,1170647,1171692,1172233-1172234,1172236,1172269,1172278,1172282,1172556,1172610,1172664,1172689,1172711,1173020-1173021,1173082,1173088,1173090,1173096 ,1173241,1173256,1173288,1173333,1173342,1173461,1173614,1173630,1173659,1173722,1174061,1174239,1174322,1174325,1174329-1174330,1174337-1174339,1174343,1174353,1174799,1174882,1174884,1174983,1175155,1175158,1175167,1175182,1175190,1175201,1175272,1175275,1175283,1175582,1175589-1175590,1175594,1175602,1175613,1175633,1175690,1175713,1175798,1175889,1175896,1175907,1176584,1176590,1176799,1177050,1177060,1177125,1177152,1177160,1177245,1177850,1177862,1177978,1178209,1178228,1178233,1178449,1178542,1178681,1178684,1178721,1179268,1179274,1180261,1180865,1180891,1180894,1180907,1181028,1181123,1181125,1181136,1181291,1181743,1182796,1183078,1183105,1183142,1183328,1183339-1183340,1183492-1183494,1183605,1184917,1184919,1185018,1185020,1185200,1185588,1185626,1185756,1185758,1186011,1186042-1186045,1186104,1186123,1186137,1186153,1186254,1186257,1186377-1186379,1186479-1186480,1186712,1186743,1186750,1186763,1186890-1186892,1186894,1186949,1187018,1187027-1187028,1187381,1187 753,1187755,1187775,1187801,1187806,1187809,1187827,1188301,1188303-1188305,1188399,1188822,1188930-1188931,1189116,1189129,1189183,1189240,1189256,1189386,1189413-1189414,1189477,1189685,1189805,1189857,1189864,1189882,1190034,1190185,1190279,1190339,1190371,1190388-1190389,1190474,1190481,1194915,1195222-1195223,1195531,1195899,1195905,1195943,1195949,1195953,1195955,1195965,1195968,1196175,1196212,1196223,1196304-1196305,1196735,1196825,1196827,1197158,1197261,1197263,1197299-1197300,1197305,1197339-1197340,1197343,1197382,1197386-1197387,1197480,1197578,1198497,1198528,1198552,1198602,1198604,1198607,1198622,1198640,1198696,1198707,1199418,1199432,1199436,1199513,1199529,1199980,1199996,1200056,1200089,1200106-1200107,1200263,1200316,1200320,1200398-1200399,1200445-1200446,1200555,1200627,1200696,1200725,1200937,1200941,1201069,1201087,1201180,1201235-1201237,1201508,1201521,1201542,1201545-1201546,1201548,1201555-1201556,1201568,1201576,1201608,1201921-1201922,1201931,1 202035,1202039,1202271,1202565,1202578,1202705,1202828,1202860,1203047-1203052,1203078,1203091,1203253,1203278,1204182,1204856,1204867,1204936,1204938,1204982,1205033,1205065,1205082,1205097,1205112,1206200,1207692,1208046,1208073,1208096,1208114,1208145,1208772,1209194,1209277-1209278,1209686-1209731,1210894,1212091,1212095,1212099,1212118,1213469,1213906,1214853,1214855,1214864,1215115,1215118-1215119,1215121,1220293,1220295,1221038,1221842,1222189,1222201,1222276,1222300,1222690,1222850,1222852,1222855 +/tomcat/trunk:1156115,1156171,1156276,1156304,1156519,1156530,1156602,1157015,1157018,1157151,1157198,1157204,1157810,1157832,1157834,1157847,1157908,1157939,1158155,1158160,1158176,1158195,1158198-1158199,1158227,1158331,1158334-1158335,1158426,1160347,1160592,1160611,1160619,1160626,1160639,1160652,1160720-1160721,1160772,1160774,1160776,1161303,1161310,1161322,1161339,1161486,1161540,1161549,1161584,1162082,1162149,1162169,1162721,1162769,1162836,1162932,1163630,1164419,1164438,1164469,1164480,1164567,1165234,1165247-1165248,1165253,1165273,1165282,1165309,1165331,1165338,1165347,1165360-1165361,1165367-1165368,1165602,1165608,1165677,1165693,1165721,1165723,1165728,1165730,1165738,1165746,1165765,1165777,1165918,1165921,1166077,1166150-1166151,1166290,1166366,1166620,1166686,1166693,1166752,1166757,1167368,1167394,1169447,1170647,1171692,1172233-1172234,1172236,1172269,1172278,1172282,1172556,1172610,1172664,1172689,1172711,1173020-1173021,1173082,1173088,1173090,1173096 ,1173241,1173256,1173288,1173333,1173342,1173461,1173614,1173630,1173659,1173722,1174061,1174239,1174322,1174325,1174329-1174330,1174337-1174339,1174343,1174353,1174799,1174882,1174884,1174983,1175155,1175158,1175167,1175182,1175190,1175201,1175272,1175275,1175283,1175582,1175589-1175590,1175594,1175602,1175613,1175633,1175690,1175713,1175798,1175889,1175896,1175907,1176584,1176590,1176799,1177050,1177060,1177125,1177152,1177160,1177245,1177850,1177862,1177978,1178209,1178228,1178233,1178449,1178542,1178681,1178684,1178721,1179268,1179274,1180261,1180865,1180891,1180894,1180907,1181028,1181123,1181125,1181136,1181291,1181743,1182796,1183078,1183105,1183142,1183328,1183339-1183340,1183492-1183494,1183605,1184917,1184919,1185018,1185020,1185200,1185588,1185626,1185756,1185758,1186011,1186042-1186045,1186104,1186123,1186137,1186153,1186254,1186257,1186377-1186379,1186479-1186480,1186712,1186743,1186750,1186763,1186890-1186892,1186894,1186949,1187018,1187027-1187028,1187381,1187 753,1187755,1187775,1187801,1187806,1187809,1187827,1188301,1188303-1188305,1188399,1188822,1188930-1188931,1189116,1189129,1189183,1189240,1189256,1189386,1189413-1189414,1189477,1189685,1189805,1189857,1189864,1189882,1190034,1190185,1190279,1190339,1190371,1190388-1190389,1190474,1190481,1194915,1195222-1195223,1195531,1195899,1195905,1195943,1195949,1195953,1195955,1195965,1195968,1196175,1196212,1196223,1196304-1196305,1196735,1196825,1196827,1197158,1197261,1197263,1197299-1197300,1197305,1197339-1197340,1197343,1197382,1197386-1197387,1197480,1197578,1198497,1198528,1198552,1198602,1198604,1198607,1198622,1198640,1198696,1198707,1199418,1199432,1199436,1199513,1199529,1199980,1199996,1200056,1200089,1200106-1200107,1200263,1200316,1200320,1200398-1200399,1200445-1200446,1200555,1200627,1200696,1200725,1200937,1200941,1201069,1201087,1201180,1201235-1201237,1201508,1201521,1201542,1201545-1201546,1201548,1201555-1201556,1201568,1201576,1201608,1201921-1201922,1201931,1 202035,1202039,1202271,1202565,1202578,1202705,1202828,1202860,1203047-1203052,1203078,1203091,1203253,1203278,1204182,1204856,1204867,1204936,1204938,1204982,1205033,1205065,1205082,1205097,1205112,1206200,1207692,1208046,1208073,1208096,1208114,1208145,1208772,1209194,1209277-1209278,1209686-1209731,1210894,1212091,1212095,1212099,1212118,1213469,1213906,1214853,1214855,1214864,1215115,1215118-1215119,1215121,1220293,1220295,1221038,1221842,1222189,1222201,1222276,1222300,1222690,1222850,1222852,1222855,1224607 Modified: tomcat/tc7.0.x/trunk/webapps/docs/manager-howto.xml URL: http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/webapps/docs/manager-howto.xml?rev=1224608&r1=1224607&r2=1224608&view=diff ============================================================================== --- tomcat/tc7.0.x/trunk/webapps/docs/manager-howto.xml (original) +++ tomcat/tc7.0.x/trunk/webapps/docs/manager-howto.xml Sun Dec 25 13:33:20 2011 @@ -111,22 +111,62 @@ With Ant</a> for more information.</li> anyone on the Internet to execute the Manager application on your server. Therefore, the Manager application is shipped with the requirement that anyone who attempts to use it must authenticate themselves, using a username and -password that have the role <strong>manager-script</strong> associated with -them. Further, there is no username in the default users file -(<code>$CATALINA_BASE/conf/tomcat-users.xml</code>) that is assigned this -role. Therefore, access to the Manager application is completely disabled +password that have one of <strong>manager-**</strong> roles associated with +them (the role name depends on what functionality is required). +Further, there is no username in the default users file +(<code>$CATALINA_BASE/conf/tomcat-users.xml</code>) that is assigned to those +roles. Therefore, access to the Manager application is completely disabled by default.</p> +<p>You can find the role names in the <code>web.xml</code> file of the Manager +web application. The available roles are:</p> + +<ul> + <li><strong>manager-gui</strong> — Access to the HTML interface.</li> + <li><strong>manager-status</strong> — Access to the "Server Status" + page in the HTML interface only.</li> + <li><strong>manager-script</strong> — Access to the tools-friendly + plain text interface, that is described in this document.</li> + <li><strong>manager-jmx</strong> — Access to JMX proxy interface.</li> +</ul> + +<p>The HTML interface is protected against CSRF (Cross-Site Request Forgery) +attacks, but the text and JMX interfaces cannot be protected. To maintain +the CSRF protection:</p> + +<ul> + <li>Users with the <strong>manager-gui</strong> role should not be granted + the <strong>manager-script</strong> or <strong>manager-jmx</strong> + roles.</li> + <li>If you use web browser to access the Manager application using + a user that has either <strong>manager-script</strong> or + <strong>manager-jmx</strong> roles (for example for testing + the plain text or JMX interfaces), + then all windows of the browser MUST be closed afterwards to terminate + the session.</li> +</ul> + +<p>Note that JMX proxy interface is effectively low-level root-like +administrative interface of Tomcat. One can do a lot, if he knows +what commands to call. You should be cautious when enabling the +<strong>manager-jmx</strong> role.</p> + <p>To enable access to the Manager web application, you must either create -a new username/password combination and associate the role name -<strong>manager-script</strong> with it, or add the -<strong>manager-script</strong> role -to some existing username/password combination. Exactly where this is done -depends on which <code>Realm</code> implementation you are using:</p> +a new username/password combination and associate one of the +<strong>manager-**</strong> roles with it, or add a +<strong>manager-**</strong> role +to some existing username/password combination. +As the majority of this document describes the commands of plain textual +interface, let the role name for further example to be +<strong>manager-script</strong>. +Exactly how the usernames/passwords are configured depends on which +<code>Realm</code> implementation you are using:</p> <ul> -<li><em>MemoryRealm</em> - If you have not customized your - <code>$CATALINA_BASE/conf/server.xml</code> to select a different one, - Tomcat defaults to an XML-format file stored at +<li><em>MemoryRealm</em> — This one is configured in the default + <code>$CATALINA_BASE/conf/server.xml</code>. + If you have not configured it differently, or replaced it with + a different <code>Realm</code> implementation, this realm + reads an XML-format file stored at <code>$CATALINA_BASE/conf/tomcat-users.xml</code>, which can be edited with any text editor. This file contains an XML <code><user></code> for each individual user, which might @@ -139,12 +179,12 @@ depends on which <code>Realm</code> impl add the <strong>manager-script</strong> role to the comma-delimited <code>roles</code> attribute for one or more existing users, and/or create new users with that assigned role.</li> -<li><em>JDBCRealm</em> - Your user and role information is stored in +<li><em>JDBCRealm</em> — Your user and role information is stored in a database accessed via JDBC. Add the <strong>manager-script</strong> role to one or more existing users, and/or create one or more new users with this role assigned, following the standard procedures for your environment.</li> -<li><em>JNDIRealm</em> - Your user and role information is stored in +<li><em>JNDIRealm</em> — Your user and role information is stored in a directory server accessed via LDAP. Add the <strong>manager-script</strong> role to one or more existing users, and/or create one or more new users with this role assigned, following @@ -158,8 +198,8 @@ as long as they identify a valid user in the role <strong>manager-script</strong>.</p> <p>In addition to the password restrictions the Manager web application -could be restricted by the remote IP address or host by adding a -<code>RemoteAddrValve</code> or <code>RemoteHostValve</code>. +could be restricted by the <strong>remote IP address</strong> or host by adding +a <code>RemoteAddrValve</code> or <code>RemoteHostValve</code>. See <a href="config/valve.html#Remote_Address_Filter">valves documentation</a> for details. Here is an example of restricting access to the localhost by IP address:</p> @@ -170,17 +210,6 @@ an example of restricting access to the </Context> </pre> -<p>The HTML interface is protected against CSRF but the text and JMX interfaces -are not. To maintain the CSRF protection:</p> - -<ul> - <li>users with the <code>manager-gui</code> role should not be granted either the - <code>manager-script</code> or <code>manager-jmx</code> roles.</li> - <li>if the text or jmx interfaces are accessed through a browser (e.g. for - testing since these interfaces are intended for tools not humans) then the - browser must be closed afterwards to terminate the session.</li> -</ul> - </section> --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org