Adobe 38043740 Lockdown Guide - Page 67

Server Settings > Mail, 5.6 Data & Services > Data Sources, Enable SSL

Page 67 highlights

Setting Default Disable updating ColdFusion internal cookies using ColdFusion tags/function s. Checked on Secure Profile Recommendation Description Checked if all sites require SSL. You can use this feature to prevent a developer from overriding your global session cookie security settings. 5.5 Server Settings > Mail Setting Default Enable SSL socket connections to mail server Unchecked Enable TLS Unchecked connection to mail server Recommendation Description Checked if supported Consider enabling SSL or TLS encryption for sending mail with ColdFusion. Checked if supported Consider enabling SSL or TLS encryption for sending mail with ColdFusion. 5.6 Data & Services > Data Sources Setting Default Login 30 Seconds Timeout (sec) Recommendation Description 5 Seconds Decrease this value to be less than the Timeout Requests after setting. 67

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

67
Setting
Default
Recommendation
Description
Disable
updating
ColdFusion
internal
cookies using
ColdFusion
tags/function
s.
Checked on
Secure Profile
Checked if all sites
require SSL.
You can use this feature to prevent a
developer from overriding your
global session cookie security
settings.
5.5 Server Settings > Mail
Setting
Default
Recommendation
Description
Enable SSL
socket
connections
to mail server
Unchecked
Checked if
supported
Consider enabling SSL or TLS
encryption for sending mail with
ColdFusion.
Enable TLS
connection to
mail server
Unchecked
Checked if
supported
Consider enabling SSL or TLS
encryption for sending mail with
ColdFusion.
5.6 Data & Services > Data Sources
Setting
Default
Recommendation
Description
Login
Timeout (sec)
30 Seconds
5 Seconds
Decrease this value to be less than
the
Timeout Requests after
setting.