Is Tomcat Security Manager supported?

cancel
Showing results for 
Search instead for 
Did you mean: 
ibar78
Member II

Is Tomcat Security Manager supported?

Jump to solution

Hi

A security company has performed security checks on Alfresco and they have noted that Tomcat Security Manager has not been enabled. Can someone confirm whether Alfresco works reliably with Security Manager enabled?

We are currently running Alfresco v4.2.5.2 on Red Hat 6.8 (Santiago)

Many thanks

1 Solution

Accepted Solutions
afaust
Master

Re: Is Tomcat Security Manager supported?

Jump to solution

It always depends on what kind of security policy you are going to use with a SecurityManager. Since Alfresco is using a collection of 3rd party open source / industry Standard libraries you would have to deal with all their specific approaches to providing their functionality. From reflection to creating custom threads (instead of e.g. using container provided executors), arbitrary file system accesses and sub-process initiation, there are quite a lot of permission you would have to grant to various libraries. AFAIK there is no comprehensive example policy file provided anywhere that you could use as a starting point.

View solution in original post

1 Reply
afaust
Master

Re: Is Tomcat Security Manager supported?

Jump to solution

It always depends on what kind of security policy you are going to use with a SecurityManager. Since Alfresco is using a collection of 3rd party open source / industry Standard libraries you would have to deal with all their specific approaches to providing their functionality. From reflection to creating custom threads (instead of e.g. using container provided executors), arbitrary file system accesses and sub-process initiation, there are quite a lot of permission you would have to grant to various libraries. AFAIK there is no comprehensive example policy file provided anywhere that you could use as a starting point.