03-28-2017 04:35 AM
Hi
A security company has performed security checks on Alfresco and they have noted that Tomcat Security Manager has not been enabled. Can someone confirm whether Alfresco works reliably with Security Manager enabled?
We are currently running Alfresco v4.2.5.2 on Red Hat 6.8 (Santiago)
Many thanks
03-28-2017 05:15 AM
It always depends on what kind of security policy you are going to use with a SecurityManager. Since Alfresco is using a collection of 3rd party open source / industry Standard libraries you would have to deal with all their specific approaches to providing their functionality. From reflection to creating custom threads (instead of e.g. using container provided executors), arbitrary file system accesses and sub-process initiation, there are quite a lot of permission you would have to grant to various libraries. AFAIK there is no comprehensive example policy file provided anywhere that you could use as a starting point.
03-28-2017 05:15 AM
It always depends on what kind of security policy you are going to use with a SecurityManager. Since Alfresco is using a collection of 3rd party open source / industry Standard libraries you would have to deal with all their specific approaches to providing their functionality. From reflection to creating custom threads (instead of e.g. using container provided executors), arbitrary file system accesses and sub-process initiation, there are quite a lot of permission you would have to grant to various libraries. AFAIK there is no comprehensive example policy file provided anywhere that you could use as a starting point.
Explore our Alfresco products with the links below. Use labels to filter content by product module.