jboss monitoring and security

jboss monitoring and security

My understanding of the jboss monitoring component is that you use the http invoker service to obtain mbean information. Our jboss servers have tomcat running on port 80 and we have to run the invoker servlet on this port too. Does this not present a security problem? Is there a better way to do this or am I missing something? I can switch on authentication for the servlet but then I can't see where I would add the information in application manager. How are people dealing with this issue?

thank you

                New to ADSelfService Plus?