What is Tomcat?
Tomcat is free software that runs Java web applications. Many sites use it. Like any program on the internet, it needs care. Attackers look for old versions and weak settings.
Warning: Back up your Tomcat folder and your applications before you change anything.
Steps
- Keep it updated. New Tomcat releases fix security bugs. Check your version often.
This prints the version. Your install path may differ./opt/tomcat/bin/version.sh - Run it as a normal user. Never run Tomcat as root. If someone breaks in, they get fewer powers. Create a user such as
tomcatfor this job. - Remove sample apps. In the
webappsfolder, delete thedocs,examples,host-managerandmanagerfolders if you do not need them. - Protect the Manager app. If you keep it, use a strong password. Limit who can open it by IP address, in the file
META-INF/context.xmlof that app. - Close the shutdown port. Tomcat listens on port 8005 for a shutdown word. In
conf/server.xml, change the word to a long random one, or set the port to-1to turn it off. - Hide version details. In
server.xml, setserver=""in the Connector line. This stops Tomcat telling visitors which version it is. - Use HTTPS. Put a TLS certificate on the site, so data is scrambled. Many people put Apache or Nginx in front of Tomcat to handle this.
- Block direct access to Tomcat ports. Close 8080 and 8009 in the firewall if Apache or Nginx forwards the traffic.
- Turn off directory listing. In
conf/web.xml, set thelistingsvalue of the default servlet tofalse. - Restart Tomcat and test your site.
This applies the changes. Your service name may differ.systemctl restart tomcat
Tip: Check the Tomcat logs in the
logs folder from time to time. Many failed logins may mean someone is guessing passwords.Need help? Open a support ticket.
Quick recap
- Update Tomcat often.
- Do not run it as root.
- Remove sample and manager apps you do not use.
- Close or protect extra ports.
- Use HTTPS and hide version details.