is removing the manager war an option for you? i don't think it's required for operation. you could also rename it so that it's in a different url path than the default
On Wed, Feb 22, 2023 at 12:58 PM Mark Thomas <ma...@apache.org> wrote: > On 22/02/2023 17:49, James H. H. Lampert wrote: > > On 2/22/23 9:23 AM, Mark Thomas wrote: > >> Fire them and hire a security consultant with a proper understanding > >> of risk? > > > > Pardon my Yiddish, but "Fun dayn moyl in Gots oyern." (From your mouth > > to God's ears. Such a colorful language.) > > > > But just because you're paranoid doesn't mean they're not out to get you. > > > > So just add > > > > denyStatus="404" > > to the RemoteAddrValve? > > Exactly. > > Mark > > --------------------------------------------------------------------- > To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org > For additional commands, e-mail: users-h...@tomcat.apache.org > >