Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This come from this archive, I copied and updated it here to be sure to have this always on hand.This is an outline of a few steps that should be taken to ensure that live deployed OFBiz systems do not leave open access for others to abuse.

...

  • Change the port from 8080 to 80
  • Possibly add or move a webapp to respond to "/".
  • This is now also in the system "Started If you uncommented ou the BeanShell telnet service on 9989, 9990, BeanShell service ports are not secure. Please , so protect the ports " and requires attention for deployment!
  • If you loaded the demo data be sure to disable all user logins except "admin" and maybe "flexadmin" Be sure to change their passwords if you expose your server to Internet
  • This page coumd may not be uptodate to the latest version of OFBiz at all times therefore you should always be careful and check your system for other possible holes.

To think about:

...

  • Maybe generate a "production" script to modify and/or remove these logins for a production site Add a brief description (or a link to one) of each webapp to assist the user to determine which ones they need and which ones they don't.