Both HTTP and HTTPS connectors provide login and password-based authentication. The server component contains the list of allowed login identifiers and their password. Management applications must specify the login and password information in the address object when establishing a connection.
If the list of recognized clients is empty, no authentication is performed and access is granted to all clients; this is the default behavior.