In order to do an SSL Configuration testing under Tomcat, is this all mandatory?
This below line is taken from a website:
In order to do this
No, it's not necessary. It means that your web application only available through HTTPS (and not available through HTTP).
If you omit the <transport-guarantee>CONFIDENTIAL</transport-guarantee> tag (or the whole <security-constraint>) your application will be available through both HTTP and HTTPS. If your web.xml contains <transport-guarantee>CONFIDENTIAL</transport-guarantee> Tomcat automatically redirects the requests to the SSL port if you try to use HTTP.
Please note that the default Tomcat configuration does not enable the SSL connector, you have to enable it manually. Check the SSL Configuration HOW-TO for the details.
If you check closer, the blog explains that further:
Any resource in your application can be accessed only with HTTPS be it Servlets or JSP’s. The term
CONFIDENTIALis the term which tells the server to make the application work onSSL. If you want to turn theSSLmode for this application off then just turn don’t delete the fragment. Just put the value asNONEinstead ofCONFIDENTIAL.