users@glassfish.java.net

Official instructions on how to secure SJSAS / Glassfish V2?

From: <glassfish_at_javadesktop.org>
Date: Tue, 04 Dec 2007 05:08:43 PST

I'm new to SJSAS/Glassfish, and have installed SJSAS 9.1 on Solaris 10, but am now looking to secure it. I can't find any official documentation (or indeed any documentation) on securing it, so I'm having to follow my intuition.

I've managed to go through and manually change each port (ORB, JMX etc) to listen just on 127.0.0.1. I'm slightly uncomfortable with the fact that I had to start the admin console in order to secure it. In addition, the JMX restriction broke the ability to start the domain, until I ensured that my hostname resolved to 127.0.0.1.

So it's now sort of working, but I feel that I've had to struggle a bit, and there must be some "official documentation" or trick that I'm missing. Can anyone give me a pointer here?

Thanks!
Justin
[Message sent by forum member 'justinsb' (justinsb)]

http://forums.java.net/jive/thread.jspa?messageID=248411