天天看点

jboss安全基本配置,禁用jmx、web console、status

1.改jmx、web-console密码/opt/jboss-4.2.3.GA/server/node1/conf/props

jbossws-users.properties 

jmx-console-users.properties

2.取消统计status:

/opt/jboss-4.2.3.GA/server/node1/deploy/jboss-web.deployer/ROOT.war/WEB-INF

下面web.xml

<!–

<servlet>

<servlet-name>Status Servlet</servlet-name>

<servlet-class>org.jboss.web.tomcat.service.StatusServlet</servlet-class>

</servlet>

<servlet-mapping>

<servlet-name>Status Servlet</servlet-name>

<url-pattern>/status</url-pattern>

</servlet-mapping>

–>

3.启用jmx密码管理:

/opt/jboss-4.2.3.GA/server/node1/deploy/jmx-console.war/WEB-INF

3.1. jboss-web.xml 取消注释: <security-domain>java:/jaas/jmx-console</security-domain>

3.2. web.xml 取消注释: <security-constraint>

4.启用web-console密码管理:

/opt/jboss-4.2.3.GA/server/node1/deploy/management/console-mgr.sar/web-console.war/WEB-INF

4.1.jboss-web.xml取消注释: <security-domain>java:/jaas/web-console</security-domain>

4.2.web.xml取消注释: <security-constraint>

本人新个人站点地址:http://sagacitytree.org/?p=145

欢迎各位莅临。