Supplement · Tomcat

Hardening, management plane và safe defaults

Tomcat hardening bắt đầu bằng giảm exposed surface, current patch level và least privilege; không phải một danh sách header rời rạc.

Security

Installation surface

Loại manager, host-manager, docs, examples nếu không dùng. Chạy non-root user, chỉ write temp/log/work cần thiết, bảo vệ conf/secrets và dùng image/read-only filesystem phù hợp. Không expose shutdown/management ports.

Manager, JMX và Realms

Management plane cần network isolation, strong authentication/authorization, TLS và audit. Tách deploy credentials khỏi monitoring. JMX remote config sai có thể mở code/data access; prefer local/agent-controlled paths.

Request security

Đặt header/body/count/time limits thống nhất với proxy; safe error pages; encode access log để tránh injection và scrub credentials/session/query PII. Disable TRACE/listing/unused methods/features theo application contract.

Patch và verification

Inventory Tomcat/JDK/native library/version provenance, subscribe security advisories và test upgrade. Scan effective deployment surface, ports, permissions, TLS, default apps và negative requests; config file tồn tại không chứng minh runtime applied.

Security Considerations · Tomcat 10 Security · Manager HOW-TO
← TLS/proxyOperations →