As a PCI requirement, I wanted to get the tomcat deployment manager on HTTPS as the password was flowing in plain-text.

I tried few resources like this.

My current connector is as given below:

<Connector protocol="org.apache.coyote.ajp.AjpProtocol" executor="tomcatThreadPool"  port="8301" address=""
        tomcatAuthentication="false" redirectPort="443" proxyPort="443" connectionTimeout="1000" keepAliveTimeout="300000" packetSize="21000" maxHttpHeaderSize="3600000" />

and I can access the manager on given port successfully.

I changed the security-contraint to enable HTTPS by adding the below.

        <web-resource-name>Protected Context</web-resource-name>
      <!-- auth-constraint goes here if you requre authentication -->

Please point out if I am missing anything. Any blog or documentation of some sort will help as well.

0 Answers0