Adobe 38043740 Lockdown Guide - Page 25

Remove Request Filtering Rule for ColdFusion Administrator Site, Require SSL, Require 128-bit SSL

Page 25 highlights

Select Require SSL and Require 128-bit SSL and click Apply. Visit https://127.0.0.1/ and ensure that it requires SSL and authentication. Remove Request Filtering Rule for ColdFusion Administrator Site Because we have specified that the URI /CFIDE/administrator is blocked on a global level using IIS Request Filtering, we need to enable that URI only on our cfadmin web site. To do this click on the cfadmin website under sites, and click on Request Filtering. Select the URL tab and click on the rule matching /CFIDE/administrator and click the Remove button. 25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

25
Select
Require SSL
and
Require 128-bit SSL
and click Apply.
Visit
/ and ensure that it requires SSL and authentication.
Remove Request Filtering Rule for ColdFusion Administrator Site
Because we have specified that the URI
/CFIDE/administrator
is blocked on a global level using IIS
Request Filtering
, we need to enable that URI only on our cfadmin web site. To do this click on the
cfadmin
website under sites, and click on
Request Filtering
. Select the
URL
tab and click on the rule matching
/CFIDE/administrator
and click the
Remove
button.