
114
CONFIGURING AND ADMINISTERING COLDFUSION 10
Administering Security
L
ast
u
p
dated
7/9/2
01
2
Note:
Secure Profile disables Directory Browsing for a stand alone ColdFusion installation with built-in web server.
Using sandbox security
Sandbox security (called Resource security in the Standard Edition) uses the location of your ColdFusion pages to
control access to ColdFusion resources. A
sandbox
is a designated directory of your site to which you apply security
restrictions. Sandbox security lets you specify which tags, functions, and resources (for example, files, directories, and
data sources) can be used by ColdFusion pages located in and under the designated directory.
To use sandbox security in the J2EE editions, the application server must be running a security manager
(
java.lang.SecurityManager
) and you define the following JVM arguments (for Tomcat, this is the java.args line
in the
cf_root
/cfusion/bin/jvm.config file):
-Djava.security.manager "-Djava.security.policy=
cf_root
/WEB-
INF/cfusion/lib/coldfusion.policy" "-Djava.security.auth.policy=
cf_root
/WEB-
INF/cfusion/lib/neo_jaas.policy"
10
Enable WebSocket Server
Server Settings
>
WebSocket
Enabled
Disabled
N/A
11
Start Flash Policy Server
Server Settings
>
WebSocket
Enabled
Disabled
N/A
12
Allowed SQL (all settings)
Data & Services
>
Data
Sources
>
[database]
>
Advanced Settings
Enabled.
Create, Drop, Alter,
Grant, Revoke,
Stored Procedures
are disabled
Retained if specified
13
Enable Robust Exception
Information
Debugging & Logging
>
Debug Output Settings
Disabled
Disabled
Overwritten
14
Enable CFSTAT
Debugging & Logging
>
Debug Output Settings
Enabled.
Disabled
Overwritten
15
Select the type of
Administrator authentication
Security
>
Administrator
Use a single
password only
Separate user name
and password
authentication
(allows multiple
users)
N/A
16
Enable RDS Service
Security
>
RDS
Configurable at
install time
Disabled
N/A
17
Select the type of RDS
authentication
Security
>
RDS
Use a single
password only
Separate user name
and password
authentication
(allows multiple
users)
N/A
18
Enable ColdFusion Sandbox
Security
Security
>
Sandbox Security
Disabled
Disabled
Overwritten
19
Allowed IP addresses for
ColdFusion Administrator
access
Security
>
Allowed IP
Addresses
Not available at
install time
Available at install
time
N/A
Administrator Settings
Path
Default Admin
Profile
Secure Profile
Changes to the
setting post
migration to
ColdFusion 10