2018-06-13 18:20:45 +00:00
|
|
|
--- conf/catalina.policy.orig 2018-03-16 12:18:17.835746805 -0400
|
|
|
|
+++ conf/catalina.policy 2018-06-13 13:52:33.586872659 -0400
|
|
|
|
@@ -50,6 +50,21 @@ grant codeBase "file:${java.home}/lib/ex
|
2016-07-01 18:14:32 +00:00
|
|
|
permission java.security.AllPermission;
|
|
|
|
};
|
|
|
|
|
|
|
|
+// ========== RHEL SPECIFIC CODE PERMISSIONS =======================================
|
|
|
|
+
|
|
|
|
+// Allowing everything in /usr/share/java allows too many unknowns to be permitted
|
|
|
|
+// Specifying the individual jars that tomcat needs to function with the security manager
|
|
|
|
+// is the safest way forward.
|
2018-06-13 18:20:45 +00:00
|
|
|
+grant codeBase "file:/usr/share/java/tomcat-servlet-4.0-api.jar" {
|
2016-07-01 18:14:32 +00:00
|
|
|
+ permission java.security.AllPermission;
|
|
|
|
+};
|
2018-06-13 18:20:45 +00:00
|
|
|
+grant codeBase "file:/usr/share/java/tomcat-jsp-2.3-api.jar" {
|
2016-07-01 18:14:32 +00:00
|
|
|
+ permission java.security.AllPermission;
|
|
|
|
+};
|
2018-06-13 18:20:45 +00:00
|
|
|
+grant codeBase "file:/usr/share/java/tomcat-el-3.0-api.jar" {
|
2016-07-01 18:14:32 +00:00
|
|
|
+ permission java.security.AllPermission;
|
|
|
|
+};
|
|
|
|
+
|
|
|
|
|
|
|
|
// ========== CATALINA CODE PERMISSIONS =======================================
|
|
|
|
|