After installing new Tomcat server, there will be no user created by default to access Administrator and Manager interfaces. So after installing Tomcat this scan be first step to create Admin and Manager user accounts.
Creating Tomcat User:-
To create user account edit conf/tomcat-users.xml file in editor and copy below configuration inside <tomcat-users> </tomcat-users> tags.
tomcat-users> <!-- user manager can access only manager section --><role rolename=" manager-gui" /> <user username=" manager" password=" _SECRET_PASSWORD_" roles=" manager-gui" /> <!-- user admin can access manager and admin section both --><role rolename=" admin-gui" /> <user username=" admin" password=" _SECRET_PASSWORD_" roles=" manager-gui,admin-gui" /> < /tomcat-users>
As per above configuration user manager only can access manager web interface but admin can access both admin + manager web interface.
After making above change Stop and Start your Tomcat server.
Access Roles in Tomcat:-
Tomcat 7 and onward releases has following roles defined for accessing Tomcat Admin and Manager interfaces. Use the following roles while creating users for tomcat with specific access levels.
Roles for Admin (Host Manager) Access:
Roles for Manager (Manager App) Access: