How to avoid storing passwords in the clear for tomcat's server.xml Resource definition of a DataSource?

前端 未结 9 1955

The resource definition in tomcat\'s server.xml looks something like this...



        
9条回答
  •  陌清茗
    陌清茗 (楼主)
    2020-12-01 00:36

    Tomcat has a Password FAQ that specifically addresses your question. In short: Keep the password in the clear and properly lock-down your server.

    That page also offers some suggestions of how security-by-obscurity might be used to pass an auditor's checklist.

提交回复
热议问题