This is just a rough outline. I will be fleshing this out over the next few weeks. -- Andrew Jaquith 

!!Comments and Discussion:
!!!Operating system and servlet container 

!!Host access 

!!Directory layout 

!!Runtime security 

!Runtime users 

!Startup scripts 


!Container-managed authentication 

!!Service minimization 

!Tomcat hardening 

!!File permissions 

!Servlet logs 

!Servlet configuration directory 

!!Host-based firewall 

!IPTables example 

!!!PostgreSQL Database 

!!User and group tables 

!!Authentication configuration 

!!Servlet container realm configuration 

!!!JSPWiki Application 

!!Directory layout and permissions 

!WAR file 

!Wiki pages