Adobe 38043740 Lockdown Guide - Page 37

If you are installing on Linux with SELinux enabled, hold off on installing the apache connector

Page 37 highlights

Install the connector for IIS, you can select either All IIS websites or a specific one depending on your needs. If your web server will be hosting web sites that do not require ColdFusion, do not select all IIS websites, or be sure to manually remove ColdFusion from each site that does not require it. If any websites are added to IIS that require ColdFusion after the installation, you will need to run the web server connector tool (wsconfig.exe) again to connect ColdFusion 10 to the web site. If you are installing on Linux with SELinux enabled, hold off on installing the apache connector, this is done manually later on in this guide. For maximum security consider running the web server and ColdFusion on separate physical servers. One way to separate the public facing web server and the ColdFusion server is by using a reverse proxy. In a reverse proxy setup the ColdFusion server will still have a web server installed, however all external client requests will be handled by the proxy server, and only specific requests will be sent to the ColdFusion server for processing. Consult your web servers documentation to set up a reverse proxy. 37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

37
Install the connector for IIS, you can select either All IIS websites or a specific one depending on your needs. If
your web server will be hosting web sites that do not require ColdFusion, do not select all IIS websites, or be
sure to manually remove ColdFusion from each site that does not require it.
If any websites are added to IIS that require ColdFusion after the installation, you will need to run the web
server connector tool (wsconfig.exe) again to connect ColdFusion 10 to the web site.
If you are installing on Linux with SELinux enabled, hold off on installing the apache connector, this is
done manually later on in this guide.
For maximum security consider running the web server and ColdFusion on separate physical servers.
One way to separate the public facing web server and the ColdFusion server is by using a reverse proxy. In a
reverse proxy setup the ColdFusion server will still have a web server installed, however all external client
requests will be handled by the proxy server, and only specific requests will be sent to the ColdFusion server
for processing. Consult your web servers documentation to set up a reverse proxy.