You are not authorized to view this page. If you have not changed
any configuration files, please examine the file
conf/tomcat-users.xml in your installation. That
file must contain the credentials to let you use this webapp.
For example, to add the admin-gui role to a user named
tomcat with a password of s3cret, add the following to the
config file listed above.
<user username="tomcat" password="s3cret" roles="admin-gui"/>
Note that for Tomcat 7 onwards, the roles required to use the host manager
application were changed from the single admin role to the
following two roles. You will need to assign the role(s) required for
the functionality you wish to access.
The HTML interface is protected against CSRF but the text interface is not.
To maintain the CSRF protection:
- admin-gui - allows access to the HTML GUI
- admin-script - allows access to the text interface
- Users with the admin-gui role should not be granted the
- If the text interface is accessed through a browser (e.g. for testing
since this interface is intended for tools not humans) then the browser
must be closed afterwards to terminate the session.