
66
Setting
Default
Recommendation
Description
Maximum
Timeout:
Session
Variables
2 Days
Lower
Two days is generally too long for
sessions to persist. Lower session
timeouts reduce the window of risk
of session hijacking.
Default
Timeout:
Session
Variables
20 Minutes
Lower
Twenty minutes is a good default
value, but high security applications
will require a lower timeout value.
Cookie
Timeout
1440 Minutes
-1
By setting to -1 ColdFusion will set
the session cookie as a browser
session cookie, which is valid as
long as the users browser window is
open.
As of this writing you cannot specify
a value of -1 using ColdFusion
administrator, however you can set
this value by editing the
sessionCookieTimeout
value
in the
neo-runtime.xml
file.
HTTPOnly
Checked
Checked
Session cookies should always be
marked as HTTPOnly to prevent
JavaScript or other client side
technologies from accessing their
values (on supported clients).
Secure
Unchecked
Checked if all sites
require SSL.
A client will only transmit a
secure
cookie over a secured connection
(eg SSL).
Summary of Contents for 38043740 - ColdFusion Standard - Mac
Page 5: ...5 ...
Page 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Page 26: ...26 ...
Page 33: ...33 ...
Page 38: ...38 ...