users@glassfish.java.net

Looking for definitive document on securing a Glassfish V3 server

From: Farrukh Najmi <farrukh_at_wellfleetsoftware.com>
Date: Wed, 30 Jun 2010 15:16:37 -0400

Hello,

One of my government customers will not deploy my company's software
product on Glassfish V3 and would only consider deploying on Tomcat
because he can use the following definitive document to secure the
Tomcat instance:

CIS Apache Tomcat Server Benchmark v.1.0.0:
http://cisecurity.org/en-us/?route=downloads.show.single.tomcat.100

I am wondering if there is a similar definitive document on securing
Glassfish V3 server that I could refer my customer to so I can encourage
them to move from Tomcat to Glassfish V3. I see the following link in
google serach:

http://docs.sun.com/app/docs/doc/820-4496/beabg?l=en&n=1&a=view

However, it would be nice to get a link to a document from the Center
for Internet Security (like the Tomcat one I cited above).

Please send me any recommended documents that will be relevant to my
issue. Thank you for your help.

-- 
Regards,
Farrukh
Web: http://www.wellfleetsoftware.com