Tomcat 6.0.30 manager app

Print Friendly, PDF & Email

Just seen this message when attempting to debug a manager app problem:

Note that for Tomcat 6.0.30 onwards, the roles required to use the manager application were changed from the single manager
role to the following four roles. You will need to assign the role(s) required for the functionality you wish to access.
* manager-gui – allows access to the HTML GUI and the status pages
* manager-script – allows access to the text interface and the status pages
* manager-jmx – allows access to the JMX proxy and the status pages
* manager-status – allows access to the status pages only

The HTML interface is protected against CSRF but the text and JMX interfaces are not. To maintain the CSRF protection:
* The deprecated manager role should not be assigned to any user.
* Users with the manager-gui role should not be granted either the manager-script or manager-jmx roles.
* If the text or jmx interfaces are accessed through a browser (e.g. for testing since these interfaces are intended for
tools not humans) then the browser must be closed afterwards to terminate the session.

I’ve fixed instances on tc-prod0 to use the new role but I’ve left the remaining servers. If you are having problems accessing a tomcat manager app via http://tomcatserver:8901/manager/html try changing the auth config in /usr/local/projects/project/tomcat6/instance/conf/tomcat-users.xml to something like the above suggestion.

About this entry