You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Tomcat配置问题:访问未授权,输入凭证后无法打开页面

Fixing "Apache Tomcat configuration: Access not authorized" Error

Hey there! Let's break down why your root/tomcat credentials aren't working and get you access to the Tomcat console. This issue almost always traces back to missing or incorrect user role assignments in Tomcat's core configuration files. Here's how to fix it step by step:

Step 1: Locate and Edit the Tomcat Users Config

Head to your Tomcat installation directory, navigate to the conf folder, and open the tomcat-users.xml file. This is where Tomcat stores all user accounts and their associated permissions.

Step 2: Assign the Required Roles to Your User

Chances are you created the root user but didn't grant it the specific roles needed to access the management consoles. Tomcat requires distinct roles for different admin interfaces:

  • manager-gui: Grants access to the Manager App (for deploying apps, checking server status, etc.)
  • admin-gui: Grants access to the Host Manager (for virtual host configuration)

Update your user entry to include these roles. Your config should look like this:

<user username="root" password="tomcat" roles="manager-gui,admin-gui"/>

Double-check for typos—those -gui suffixes are critical; using just manager or admin won’t work.

Step 3: Restart Tomcat

Don’t skip this! Changes to tomcat-users.xml won’t take effect until you stop and restart your Tomcat server. This is a common oversight that keeps the old config active.

Bonus: Fix Remote Access Restrictions (If Applicable)

If you’re accessing Tomcat from a remote machine (not localhost), you might hit an extra access block. By default, Tomcat’s management apps only allow local connections. To adjust this:

  1. Go to webapps/manager/META-INF/context.xml and webapps/host-manager/META-INF/context.xml
  2. Find the RemoteAddrValve section and either:
    • Add your remote IP to the allow list (e.g., allow="127\.\d+\.\d+\.\d+|::1|0:0:0:0:0:0:0:1|192.168.1.100")
    • Temporarily comment out the entire Valve block (not recommended for production, but useful for testing):
      <!-- <Valve className="org.apache.catalina.valves.RemoteAddrValve"
               allow="127\.\d+\.\d+\.\d+|::1|0:0:0:0:0:0:0:1" /> -->
      

That’s it! 9 times out of 10, missing roles are the root cause. After updating the config and restarting, your root/tomcat credentials should let you access the console without issues.

内容的提问来源于stack exchange,提问作者GNETO DOMINIQUE

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:38:26