Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-450

TomEE configuration should be secure by default & use a profile manager for development configuration

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.5.0
    • 1.5.1
    • None
    • None

    Description

      TomEE 1.5.0 default configuration is unsecure by default, at least with regard to those items:

      • it comes with predefined users tomee-admin and tomee
      • it includes tomee administration UI
        (there are probably more)

      A noticeable improvement for TomEE would be to deliver it "secure by default" and provide a profile management tool (command line is fine) to change its setup in a "developper mode" with admin users & admin UI enabled.

      IBM WebSphere has a tool called profile management tool which allows this kind of setup in a few clicks (with couple of options).

      Attachments

        Activity

          People

            romain.manni-bucau Romain Manni-Bucau
            alex.m3tal Alex the Rocker
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: