User Guide Cancel

Server Auto-Lockdown

  1. ColdFusion User Guide
  2. Introduction to ColdFusion
    1. About Adobe ColdFusion
    2. Download Adobe ColdFusion
    3. What's new in ColdFusion (2023 release)
    4. ColdFusion (2023 release) Release Notes
    5. Deprecated Features
    6. REST enhancements in ColdFusion
    7. Central Configuration Server
    8. Server Auto-Lockdown
    9. Asynchronous programming
    10. Docker images for ColdFusion
    11. SAML in ColdFusion
    12. JSON Web Tokens in ColdFusion
    13. Use SAML and LDAP in Admin
  3. Cloud Services in ColdFusion
    1. ColdFusion and GCP Storage
    2. ColdFusion and GCP Firestore
    3. ColdFusion and GCP PubSub
    4. ColdFusion and Amazon S3
    5. ColdFusion and DynamoDB
    6. ColdFusion and Amazon SQS
    7. ColdFusion and Amazon SNS
    8. ColdFusion and MongoDB
    9. ColdFusion and Azure Blob
    10. ColdFusion and Azure Service Bus
    11. Multi-cloud storage services
    12. Multi-cloud RDS databases
    13. ColdFusion and Azure Cosmos DB
  4. Install ColdFusion
    1. Install the server configuration
    2. Install ColdFusion- Zip Installer
    3. Install ColdFusion- GUI Installer
    4. CFSetup configuration tool
    5. ColdFusion Licensing and Activation
    6. ColdFusion server profiles
    7. Prepare to install ColdFusion
    8. Install the JEE configuration
    9. Install ColdFusion Express
    10. Install integrated technologies
    11. Configure your system
    12. Troubleshoot installation issues
    13. Install ColdFusion silently
    14. Install Adobe ColdFusion (2016 release) hotfix
    15. ColdFusion (2018 release) - Install JEE configuration
  5. Use ColdFusion
    1. GraphQL in ColdFusion
    2. Command Line Interface (CLI)
    3. External session storage
    4. Generate Swagger documents
    5. Language enhancements
    6. NTLM support
    7. Enhanced PDF in ColdFusion
    8. Security enhancements in ColdFusion (2016 release)
  6. Performance Monitoring Toolset
    1. Overview of ColdFusion Performance Monitoring Toolset
    2. Auto-discovery of ColdFusion nodes and clusters
    3. Code profiler in ColdFusion Performance Monitoring Toolset
    4. Configure ColdFusion Performance Monitoring Toolset settings
    5. Install ColdFusion Performance Monitoring Toolset
    6. View cloud metrics
    7. Monitor GraphQL in Performance Monitoring Toolset
    8. Configure TLS/SSL and Authentication for Elasticsearch 8.x  in Performance Monitoring Toolset
    9. View cluster and node metrics
    10. View data source metrics
    11. View external services
    12. View incoming services
    13. View list of sites and busy connections
    14. View topology of sites
    15. Datastore Health Monitoring
    16. Performance Monitoring Toolset Update 1
    17. Secure Performance Monitoring Toolset with HTTPS/SSL
    18. Performance Monitoring Toolset deployment guide
  7. Adobe ColdFusion Builder extension for Visual Studio Code
    1. Getting started with Adobe ColdFusion Builder extension for Visual Studio Code
    2. Add a ColdFusion server
    3. Project Manager
    4. Work with ColdFusion code
    5. Profile preferences
    6. Debug applications
    7. Refactoring
    8. Services Browser
    9. RDS support
    10. PMT Code Profiler integration
    11. Security Analyzer report integration
    12. Known issues in this release
  8. Use ColdFusion Builder
    1. About ColdFusion Builder
    2. System requirements | ColdFusion Builder
    3. Install ColdFusion Builder
    4. Edit code in ColdFusion Builder
    5. Manage servers in ColdFusion Builder
    6. Manage projects in ColdFusion Builder
    7. What's new in Adobe ColdFusion Builder (2018 release)
    8. Frequently Asked Questions (FAQ) | Adobe ColdFusion Builder (2018 release)
    9. Debug applications in ColdFusion Builder
    10. ColdFusion Builder workbench
    11. ColdFusion Builder extensions
    12. Debugging Perspective in ColdFusion Builder
    13. Build mobile applications using ColdFusion Builder
    14. Bundled ColdFusion Server
    15. Debug mobile applications in ColdFusion Builder
    16. Use extensions in ColdFusion Builder
  9. Coldfusion API Manager
    1. Overview of Adobe ColdFusion API Manager
    2. Features in ColdFusion API Manager
    3. Get started with ColdFusion API Manager
    4. Install ColdFusion API Manager
    5. Authentication types
    6. Create and publish APIs
    7. Administrator
    8. Subscriber
    9. Throttling and rate limiting
    10. Notifications
    11. Connectors
    12. Set up cluster support
    13. Integrate ColdFusion and API Manager
    14. Metrics and Logging in API Manager
    15. Generate Swagger documents
    16. Configure SSL
    17. Known issues in this release
    18. Policies in ColdFusion API Manager
    19. Create a Redis cluster
    20. Multitenancy in API Manager
    21. Docker images for ColdFusion API Manager
  10. Configure and administer ColdFusion
    1. Administer ColdFusion
    2. Use the ColdFusion administrator
    3. Data Source Management for ColdFusion
    4. Connect to web servers
    5. Deploy ColdFusion applications
    6. Administer ColdFusion security
    7. Basic Troubleshooting and FAQs
    8. Work with Server Manager
    9. Use multiple server instances
    10. WebSocket Enhancements (ColdFusion 11)
    11. Security Enhancements (ColdFusion 11)
    12. Work with Server Monitor
    13. ColdFusion Administrator API Reference
  11. CFML Reference
    1. Introduction to CFML Reference
      1. New functions in ColdFusion (2018 release)
      2. New and changed functions/tags in Adobe ColdFusion (2016 release)
      3. Script supported tags and functions
      4. New and changed tags/functions in ColdFusion 11
    2. Reserved words and variables
      1. Reserved words and variables
      2. Reserved words
      3. Scope-specific built-in variables
      4. Custom tag variables
      5. ColdFusion tag-specific variables
      6. CGI environment (CGI Scope) variables
    3. ColdFusion tags
      1. ColdFusion tags
      2. Tags in ColdFusion 10
      3. Tag summary
      4. Tags by function
      5. Tag changes since ColdFusion 5
      6. Tags a-b
      7. Tags c
      8. Tags d-e
      9. Tags f
      10. Tags g-h
      11. Tags i
      12. Tags j-l
      13. Tags m-o
      14. Tags p-q
      15. Tags r-s
      16. Tags t
      17. Tags u-z
    4. ColdFusion functions
      1. ColdFusion functions
      2. New functions in ColdFusion 10
      3. ColdFusion functions by category
      4. Function changes since ColdFusion 5
      5. Functions a-b
      6. Functions c-d
      7. Functions e-g
      8. Functions h-im
      9. Functions in-k
      10. Functions l
      11. Functions m-r
      12. Functions s
      13. Functions t-z
      14. BooleanFormat
    5. Ajax JavaScript functions
      1. Ajax JavaScript functions
      2. Function summary Ajax
      3. ColdFusion.Ajax.submitForm
      4. ColdFusion.Autosuggest.getAutosuggestObject
      5. ColdFusion.Layout.enableSourceBind
      6. ColdFusion.MessageBox.getMessageBoxObject
      7. ColdFusion.ProgressBar.getProgressBarObject
      8. ColdFusion.MessageBox.isMessageBoxDefined
      9. JavaScriptFunctionsinColdFusion9Update1
    6. ColdFusion ActionScript functions
      1. ColdFusion ActionScript functions
      2. CF.http
      3. CF.query
    7. ColdFusion mobile functions
      1. ColdFusion Mobile Functions
      2. Accelerometer Functions
      3. Camera Functions
      4. Connection Functions
      5. Contact Functions
      6. Event Functions
      7. File System Functions
      8. Geolocation Functions
      9. Media and Capture Functions
      10. Notification Functions
      11. Splash Screen Functions
      12. Storage Functions
    8. Application.cfc reference
      1. Application.CFC reference
      2. Application variables
      3. Method summary
      4. onAbort
      5. onApplicationEnd
      6. onApplicationStart
      7. onMissingTemplate
      8. onCFCRequest
      9. onError
      10. onRequestEnd
      11. onRequest
      12. onRequestStart
      13. onServerStart
      14. onSessionEnd
      15. onSessionStart
    9. Script functions implemented as CFCs
      1. Script Functions Implemented as CFCs
      2. Accessing the functions
      3. Function summary
      4. ftp
      5. http
      6. mail
      7. pdf
      8. query
      9. Script functions implemented as CFCs in ColdFusion 9 Update 1
      10. storedproc
    10. ColdFusion Flash Form style reference
      1. Styles valid for all controls
      2. Styles for cfform
      3. Styles for cfformgroup with horizontal or vertical type attributes
      4. Styles for box-style cfformgroup elements
      5. Styles for cfformgroup with accordion type attribute
      6. Styles for cfformgroup with tabnavigator type attribute
      7. Styles for cfformitem with hrule or vrule type attributes
      8. Styles for cfinput with radio, checkbox, button, image, or submit type attributes
      9. Styles for cftextarea tag and cfinput with text, password, or hidden type attributes
      10. Styles for cfselect with size attribute value of 1
      11. Styles for cfselect with size attribute value greater than 1
      12. Styles for cfcalendar tag and cfinput with dateField type attribute
      13. Styles for the cfgrid tag
      14. Styles for the cftree tag
      15. ColdFusion Flash Form Style Reference
    11. ColdFusion event gateway reference
      1. ColdFusion Event Gateway reference
      2. addEvent
      3. CFEvent
      4. CFEventclass
      5. Constructor
      6. Gateway development interfaces and classes
      7. getStatus
      8. setCFCPath
      9. setCFCMethod
      10. getOriginatorID
      11. getLogger
      12. getBuddyList
      13. getBuddyInfo
      14. IM gateway message sending commands
      15. IM Gateway GatewayHelper class methods
      16. onIncomingMessage
      17. onIMServerMessage
      18. onBuddyStatus
      19. onAddBuddyResponse
      20. onAddBuddyRequest
      21. IM Gateway CFC incoming message methods
      22. IM gateway methods and commands
      23. CFML CFEvent structure
      24. warn
      25. info
      26. setOriginatorID
      27. data command
      28. submit Multi command
      29. submit command
      30. setGatewayType
      31. setGatewayID
      32. setData
      33. setCFCListeners
      34. outgoingMessage
      35. getStatusTimeStamp
      36. numberOfMessagesReceived
      37. numberOfMessagesSent
      38. removeBuddy
      39. removeDeny
      40. removePermit
      41. setNickName
      42. setPermitMode
      43. setStatus
      44. SMS Gateway CFEvent structure and commands
      45. SMS Gateway incoming message CFEvent structure
      46. getStatusAsString
      47. getProtocolName
      48. getPermitMode
      49. getPermitList
      50. getNickName
      51. getName
      52. getDenyList
      53. getCustomAwayMessage
      54. getQueueSize
      55. getMaxQueueSize
      56. getHelper
      57. getGatewayType
      58. getGatewayServices
      59. getGatewayID_1
      60. getGatewayID
      61. getData
      62. getCFCTimeout
      63. setCFCTimeout
      64. getCFCPath
      65. getCFCMethod
      66. GatewayServices class
      67. Gateway interface
      68. GatewayHelper interface
      69. addPermit
      70. addDeny
      71. addBuddy
      72. error
      73. debug
      74. Logger class
      75. stop
      76. start
      77. CFML event gateway SendGatewayMessage data parameter
      78. restart
      79. fatal
      80. SMS gateway message sending commands
    12. ColdFusion C++ CFX Reference
      1. C++ class overview
      2. Deprecated class methods
      3. CCFXException class
      4. CCFXQuery class
      5. CCFXRequest class
      6. CCFXStringSet class
      7. ColdFusion C++ CFX Reference
    13. ColdFusion Java CFX reference
      1. ColdFusion Java CFX reference
      2. Class libraries overview
      3. Custom tag interface
      4. Query interface
      5. Request interface
      6. Response interface
      7. Debugging classes reference
    14. WDDX JavaScript Objects
      1. WDDX JavaScript objects
      2. JavaScript object overview
      3. WddxRecordset object
      4. WddxSerializer object
  12. Develop ColdFusion applications
    1. Introducing ColdFusion
      1. Introducing ColdFusion
      2. About ColdFusion
      3. About Internet applications and web application servers
      4. About JEE and the ColdFusion architecture
    2. Changes in ColdFusion
      1. Changes in ColdFusion
      2. Replacement of JRun with Tomcat
      3. Security enhancements
      4. ColdFusion WebSocket
      5. Enhanced Java integration
      6. ColdFusion ORM search for indexing and search
      7. Solr enhancements
      8. Scheduler enhancements
      9. Integration with Microsoft Exchange Server 2010
      10. RESTful Web Services in ColdFusion
      11. Lazy loading across client and server in ColdFusion
      12. Web service enhancements
      13. Displaying geolocation
      14. Client-side charting
      15. Caching enhancements
      16. Server update using ColdFusion Administrator
      17. Secure Profile for ColdFusion Administrator
    3. Introduction to application development
      1. Introduction to application development using ColdFusion
      2. Using the Developing ColdFusion Applications guide
      3. About Adobe ColdFusion documentation for Developers
    4. The CFML programming language
      1. The CFML programming language
      2. Elements of CFML
      3. ColdFusion variables
      4. Expressions and number signs
      5. Arrays and structures
      6. Extend ColdFusion pages with CFML scripting
      7. Regular expressions in functions
      8. ColdFusion language enhancements
      9. Built-in functions as first class citizen
      10. Data types- Developing guide
    5. Building blocks of ColdFusion applications
      1. Building blocks of ColdFusion applications
      2. Create ColdFusion elements
      3. Write and call user-defined functions
      4. Build and use ColdFusion Components
      5. Create and use custom CFML tags
      6. Build custom CFXAPI tags
      7. Use the member functions
      8. Object Oriented Programming in ColdFusion
    6. Develop CFML applications
      1. Develop CFML applications
      2. Design and optimize a ColdFusion application
      3. Handle errors
      4. Use persistent data and locking
      5. Use ColdFusion threads
      6. Secure applications
      7. Client-side CFML (for mobile development)
      8. Use the ColdFusion debugger
      9. Debugging and Troubleshooting Applications
      10. Develop globalized applications
      11. REST enhancements in ColdFusion
      12. Authentication through OAuth
      13. Social enhancements
    7. Develop mobile applications
      1. Mobile application development
      2. Build mobile applications
      3. Debug mobile applications
      4. Inspect mobile applications
      5. Package mobile applications
      6. Troubleshoot mobile applications
      7. Device detection
      8. Client-side CFML
      9. Mobile Templates
      10. Code samples to build a mobile application
    8. Access and use data
      1. Access and use data
      2. Introduction to Databases and SQL
      3. Access and retrieve data
      4. Update database
      5. Use Query of Queries
      6. Manage LDAP directories
      7. Solr search support
    9. ColdFusion ORM
      1. ColdFusion ORM
      2. Introducing ColdFusion ORM
      3. ORM architecture
      4. Configure ORM
      5. Define ORM mapping
      6. Work with objects
      7. ORM session management
      8. Transaction and concurrency
      9. Use HQL queries
      10. Autogenerate database schema
      11. Support for multiple data sources for ORM
      12. ColdFusion ORM search
    10. ColdFusion and HTML5
      1. ColdFusion and HTML 5
      2. Use ColdFusion Web Sockets
      3. Media Player enhancements
      4. Client-side charting
      5. Display geolocation data
    11. Flex and AIR integration in ColdFusion
      1. Flex and AIR integration in ColdFusion
      2. Use the Flash Remoting Service
      3. Use Flash Remoting Update
      4. Offline AIR application support
      5. Proxy ActionScript classes for ColdFusion services
      6. Use LiveCycle Data Services ES assembler
      7. Use server-side ActionScript
    12. Request and present information
      1. Request and present information
      2. Retrieve and format data
      3. Build dynamic forms with cfform tags
      4. Validate data
      5. Create forms in Flash
      6. Create skinnable XML forms
      7. Use Ajax data and development features
      8. Use Ajax User Interface components and features
    13. Office file interoperability
      1. Office file interoperability
      2. Using cfdocument
      3. Using cfpresentation
      4. Using cfspreadsheet
      5. Supported Office conversion formats
      6. SharePoint integration
    14. ColdFusion portlets
      1. ColdFusion portlets
      2. Run a ColdFusion portlet on a JBoss portal server
      3. Run a ColdFusion portlet on a WebSphere portal server
      4. Common methods used in portlet.cfc
      5. ColdFusion portlet components
      6. Support for JSR-286
    15. Work with documents, charts, and reports
      1. Work with documents, charts, and reports
      2. Manipulate PDF forms in ColdFusion
      3. Assemble PDF documents
      4. Create and manipulate ColdFusion images
      5. Create charts and graphs
      6. Create reports and documents for printing
      7. Create reports with Report Builder
      8. Create slide presentations
    16. Use web elements and external objects
      1. Use web elements and external objects
      2. Use XML and WDDX
      3. Use web services
      4. Use ColdFusion web services
      5. Integrate JEE and Java elements in CFML applications
      6. Use Microsoft .NET assemblies
      7. Integrate COM and CORBA objects in CFML applications
    17. Use external resources
      1. Send and receive e-mail
      2. Interact with Microsoft Exchange servers
      3. Interact with remote servers
      4. Manage files on the server
      5. Use event gateways
      6. Create custom event gateways
      7. Use the ColdFusion extensions for Eclipse
      8. Use the data services messaging event gateway
      9. Use the data management event gateway
      10. Use the FMS event gateway
      11. Use the instant messaging event gateways
      12. Use the SMS event gateway

 

Server Auto-Lockdown helps administrators secure their ColdFusion server installations. Using Server Auto-Lockdown, secure your servers against vulnerabilities.

Note:

To download the Server Auto-Lockdown installers, see Server Lockdown downloads.

At present the steps needed to lock down a ColdFusion server are manual. This document lists the steps to install Server Lockdown, which automates the steps needed for locking down a server.

When locking down a server manually, the steps involved are:

  • Install IIS
  • Configure IIS
  • Create user accounts
  • Set up webroot folder structure
  • Set up webroot permissions
  • Run ColdFusion installer
  • Install ColdFusion updates
  • Run webserver configuration tool (wsconfig.exe)
  • Setup file system permissions
  • Configure cf_scripts alias (linux)
  • Change registry permission (windows)
  • Specify logon user for ColdFusion services
  • Configure uniworkermap.properties (Windows)
  • Lockdown the /jakarta virtual directory (Windows)
  • Change ColdFusion Administrator settings

Instead, the Server Auto-Lockdown installer:

  • Performs all steps automatically
  • Provides settings summary
  • Rolls back to original configuration if the installer fails
  • Installs silently
  • Is available for all platforms (Windows and Linux)
  • Takes far lesser time compared to manually performing the steps

Before locking down a server, you must ensure the following, among others:

  • ColdFusion must be installed and running in Production or Production + Secure Profile.
  • A  webserver  must be installed and running.
  • ColdFusion Administrator must have been accessed after installation.

Additionally, we recommend the following pre-requisites:

  • Firewall is enabled.
  • ColdFusion, webserver , and the webroot are present in separate directories.
  • ColdFusion has the latest update installed.
  • Filesystem is NTFS.
  • In case of UNIX OS with web server as Apache, ensure that you have run Apache by using the control script (apachectl) and not the bin file (httpd).
  • Ensure that you must not enable Remote component of Administrator while installing ColdFusion.
Note:

On IIS Windows 2019, when the lockdown installer attempts to connect the web server, an exception may occurr due to missing MSVCR110.DLL

As a work-around, you may need to instal Might need to install Microsoft Visual C++ Redistributable 2011.

Windows - IIS

Follow the steps below to install Server Lockdown.

  1. To launch the installer, double-click the setup file. To proceed, click Next and accept the license agreement.

  2. Verify and review the installation pre-requisites.

  3. When you run the installer, the installer asks you for the ColdFusion installation directory. Specify the location and click Next.

  4. From the on-screen options, choose whether you wish to update ColdFusion to its latest version. Choose this option only if there is an internet connection so that you can download the latest update. If you do not have an active internet connection, specify the location of the update jar file.

    It is recommended that ColdFusion is on the latest update before starting the Server Auto-Lockdown process.

  5. From the drop-down list, choose the ColdFusion instance, which needs to be locked down. For each instance, run the server lockdown installer separately. 

    The instances that have already been locked down is displayed below the Available Instances drop-down list.

  6. Choose the web server and click Next.

  7. In case of IIS, choose the respective website(s) that needs to be configured to run as a connector with the given instance. This website(s) will be locked down along with the selected ColdFusion instance.

    To select multiple websites, press shift/alt/ctrl, and click each website.

    The website(s) with which the connector is already configured with the instance selected in Step 5 will be pre-selected. 

  8. Verify that the Application Pool details for the selected websites are correct.

    The application pool user will be used to give appropriate permissions to your IIS webroot and connector folder in [CF_Home]\config\wsconfig\[connector number]. Make sure that the name is correct. If not, your ColdFusion applications will be inaccessible. Select a path to map to your application pool.

    To proceed, click Next.

  9. Verify that the web server webroot(s) for the selected websites are correct.

    This folder must contain the webroot files, and these will be served using the connector port.

  10. The inputs entered below will be used by the installer to make a few changes to the ColdFusion Administrator settings that are recommended in the Lockdown Guide.

    The port here is the internal ColdFusion port, and not the connector port. For example, port 8500.

    We will not be changing or storing the password. We are using this password as an input. Make sure that the port is open, and ColdFusion instance which is being locked down is being served using this port.

  11. Provide the details for an OS administrator user account. This is required by the installer to make some changes in the file system. This user account must be the administrator account for the system where the installer is running. For example, in Windows, the account may be Administrator.

    The domain, in this case, is either the domain in which the administrator account is present or the Machine Name if it is a local account.

    We will not be changing or storing the password. This password is needed to roll back changes made to the registry and services in case of any error during installation.

  12. If there is an existing user for running ColdFusion services, select Yes and enter the user details. If there is no existing user, select no and enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  13. Enter the shutdown port. To proceed, click Next.

    Note:

    This should only be changed if the ColdFusion server being locked down is on an intranet, and someone else in the network might use the shutdown port. If the machine is an isolated one, there’s no need to change the shutdown port.

  14. Review the pre-installation summary and click Install to start the Server Auto-Lockdown.

Note:

After lockdown, check the installation logs in <CF_HOME>/lockdown/<INSTANCE_TO_LOCKDOWN>/logs/ folder. The log file lists the actions and the status of each action.

Windows - Apache

The following installation screens are specific to Apache. The first few screens are common to both IIS and Apache.

  1. In the step where the installer checks for webserver configurations, choose Apache. Click Install.

  2. The inputs entered below will be used by the installer to make a few changes to the ColdFusion Administrator settings that are recommended in the Lockdown Guide.

    The port here is the internal ColdFusion  port,  and not the connector port. For example, port 8500.

    We will not be changing or storing the password. We are using this password as an input. Make sure that the port is open, and ColdFusion instance which is being locked down is being served using this port.

  3. Provide the details for an OS administrator user account. This is required by the installer to make some changes in the file system. This user account must be the administrator account for the system where the installer is running. For example, in Windows, the account may be Administrator.

    The domain, in this case, is either the domain in which the administrator account is present or the Machine Name if it is a local account.

    We will not be changing or storing the password. This password is needed to roll back changes made to the registry and services in case of any error during installation.

  4. If there is an existing user for running ColdFusion services, select Yes and enter the user details. If there is no existing user, select no and enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  5. If there is an existing user for running web server, select Yes and enter the user details. If there is no existing user, select no and enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running Apache services.

    It is recommended to have different users for running ColdFusion and Apache services.

  6. Specify the path to the conf directory of Apache.

  7. Specify the path of the binary file of Apache.

  8. Specify the path to the webroot of Apache.

  9. If you want to upload files to your website, select Yes and specify the folder where these files are to be uploaded.

    By default, the option No is selected.

  10. Enter an alias for /cf_scripts/scripts to block all calls to /cf_scripts/scripts.

  11. Enter the shutdown port. To proceed, click Next.

Linux

  1. To launch the Server Auto-Lockdown installer, double-click the setup file.

  2. Verify and review the pre-requisites for installation.

  3. When you run the installer, the installer asks you for the ColdFusion installation directory. Specify the location and click Next.

  4. From the on-screen options, choose whether you wish to update ColdFusion to its latest version. Choose this option only if there is an internet connection so that you can download the latest update. If you do not have an active internet connection, specify the location of the update jar file.

    It is recommended that ColdFusion is on the latest update before starting the Server Auto-Lockdown process.

  5. From the drop-down list, choose the ColdFusion instance, which needs to be locked down. For each instance, run the server lockdown installer separately. 

    The instances that have already been locked down is displayed below the Available Instances drop-down list.

  6. Choose the web server, which in this case is Apache.

  7. The inputs entered below will be used by the installer to make a few changes to the ColdFusion Administrator settings that are recommended in the Lockdown Guide.

    The port here is the internal ColdFusion  port,  and not the connector port. For example, port 8500.

    We will not be changing or storing the password. We are using this password as an input. Make sure that the port is open, and ColdFusion instance which is being locked down is being served using this port.

  8. Provide the details for an OS administrator user account. This is required by the installer to make some changes in the file system. This user account must be the administrator account for the system where the installer is running. For example, in Windows, the account may be Administrator.

    The domain, in this case, is either the domain in which the administrator account is present or the Machine Name if it is a local account.

    We will not be changing or storing the password. This password is needed to roll back changes made to the registry and services in case of any error during installation.

    The password is optional in Linux.

  9. If there is an existing user for running ColdFusion services, select Yes and enter the user details. If there is no existing user, select no and enter the user details with  domain  name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

    The password is optional in Linux.

  10. If there is an existing user for running web server, select Yes and enter the user details. If there is no existing user, select no and enter the user details with  domain  name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

    The password is optional in Linux.

  11. Specify the path to the conf directory of Apache.

  12. Specify the path of the binary file of Apache.

  13. Specify the path to the Apache webroot.

  14. If you want to upload files to your website, select Yes and specify the folder where these files are to be uploaded.

  15. To restrict calls to /cf_scripts/scripts, enter an alias for the location.

  16. Enter the shutdown port. To proceed, click Next.

Mac OS

  1. To launch the Server Auto-Lockdown installer, double-click the setup file.

  2. Verify and review the pre-requisites for installation.

  3. When you run the installer, the installer asks you for the ColdFusion installation directory. Specify the location and click Next.

  4. From the on-screen options, choose whether you wish to update ColdFusion to its latest version. Choose this option only if there is an internet connection so that you can download the latest update. If you do not have an active internet connection, specify the location of the update jar file.

    It is recommended that ColdFusion is on the latest update before starting the Server Auto-Lockdown process.

  5. From the drop-down list, choose the ColdFusion instance, which needs to be locked down. For each instance, run the server lockdown installer separately. 

    The instances that have already been locked down is displayed below the Available Instances drop-down list.

  6. Choose the web server, which in this case is Apache.

  7. The inputs entered below will be used by the installer to make a few changes to the ColdFusion Administrator settings that are recommended in the Lockdown Guide.

    The port here is the internal ColdFusion port, and not the connector port. For example, port 8500.

    We will not be changing or storing the password. We are using this password as an input. Make sure that the port is open, and ColdFusion instance which is being locked down is being served using this port.

  8. Provide the details for an OS administrator user account. This is required by the installer to make some changes in the file system. This user account must be the administrator account for the system where the installer is running. For example, in Windows, the account may be Administrator.

    The domain, in this case, is either the domain in which the administrator account is present or the Machine Name if it is a local account.

    We will not be changing or storing the password. This password is needed to roll back changes made to the registry and services in case of any error during installation.

  9. If there is an existing user for running ColdFusion services, select Yes and enter the user details. If there is no existing user, select no and enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  10. If there is an existing user for running web server, select Yes and enter the user details. If there is no existing user, select no and enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  11. Specify the path to the conf directory of Apache.

  12. Specify the path of the binary file of Apache.

  13. Specify the path to the Apache webroot.

  14. If you want to upload files to your website, select Yes and specify the folder where these files are to be uploaded.

  15. To restrict calls to /cf_scripts/scripts, enter an alias for the location.

  16. Enter the shutdown port. To proceed, click Next.

  17. Review the pre-installation summary and click Install.

Solaris

  1. To launch the Server Auto-Lockdown installer, enter the file name in the command line.

  2. Accept the license agreement.

  3. Verify and review the pre-requisites for installation.

  4. When you run the installer, the installer asks you for the ColdFusion installation directory. Specify the location and press Enter.

  5. From the options (1-Yes or 2-No), choose whether you wish to update ColdFusion to its latest version. Choose this option only if there is an internet connection so that you can download the latest update. If you do not have an active internet connection, specify the location of the update jar file.

    It is recommended that ColdFusion is on the latest update before starting the Server Auto-Lockdown process.

  6. Enter the ColdFusion instance, which needs to be locked down. For each instance, run the server lockdown installer separately. 

  7. Enter the web server, which in this case is Apache.

  8. The inputs entered below will be used by the installer to make a few changes to the ColdFusion Administrator settings that are recommended in the Lockdown Guide.

    The port here is the internal ColdFusion port, and not the connector port. For example, port 8500.

    We will not be changing or storing the password. We are using this password as an input. Make sure that the port is open, and ColdFusion instance which is being locked down is being served using this port.

  9. Provide the details for an OS administrator user account. This is required by the installer to make some changes in the file system. This user account must be the administrator account for the system where the installer is running. 

    The domain, in this case, is either the domain in which the administrator account is present or the Machine Name if it is a local account.

    We will not be changing or storing the password. This password is needed to roll back changes made to the registry and services in case of any error during installation.

  10. If there is an existing user for running ColdFusion services, enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  11. If there is an existing user for running web server, enter the user details with domain name as the machine name. These details will be used to create a user in the Local System which will be used for running ColdFusion services

    While specifying the password, follow the password policy of your organization.

  12. Enter the path to the conf directory of Apache.

  13. Enter the path of the binary file of Apache.

  14. Enter the path of the Apache webroot.

  15. If you want to upload files to your website, choose (1-Yes or 2-No) and enter the folder where these files are to be uploaded.

  16. To restrict calls to /cf_scripts/scripts, enter an alias for the location.

  17. For entering the Shutdown port,choose (1-Yes or 2-No) or press Enter.

  18. Review the pre-installation summary and press Enter to start the installation.

Silent installation of Server Auto-Lockdown

Linux - Apache

# Silent Properties file for Adobe ColdFusion Server Auto-Lockdown Installer 
# Web Server : Apache 
# Platform : Linux 
 
INSTALLER_UI=SILENT 
 
#Enter the directory where ColdFusion is installed. Ex: /opt/coldfusion2021. 
SILENT_CF_SERVER_LOCATION= 
 
#The Web Server Apache is selected for configuring the connector in ColdFusion. 
#Apache will also be locked down along with ColdFusion. 
SERVER_APACHE=1 
SERVER_IIS=0 
 
#ColdFusion Server instance intended for Lockdown Ex:cfusion 
APP_SERVER_INSTANCE= 
 
#Update ColdFusion to the latest update. Allowed : 1, if you want to update ColdFusion, 0 if not. 
UPDATE_CF_TRUE=1 
 
#Allowed : 1 for Automatic Update, 0 for Manually updating ColdFusion 
AUTO_UPDATE_CF_TRUE=1 
 
#If auto-update is false, provide the path where hotfix.jar is present. Give full path. 
HF_UPDATE_JAR_PATH= 
 
#Apache Windows 
 
#ColdFusion Configuration 
#Enter the ColdFusion Administrator credentials and the built-in Web Server port. 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT= 
 
#OS Administrator Account Details. 
#Enter the user account details of the OS administrator.  
SYSTEM_ADMIN_USER= 
SYSTEM_ADMIN_PWD= 
SYSTEM_ADMIN_DOMAIN= 
 
# Allowed :1 if you have a user already created for running CF Services, 0 otherwise. 
USER_CF_SERVICE_TRUE= 
 
# Details for User for configuring ColdFusion services and file system permissions. If not existing, a user will be created 
CF_USER_UNAME= 
CF_USER_PWD= 
CF_USER_GRP= 
 
# Enter the user account to run Web Server with, post lockdown. 
#The user account will be granted file system permissions to the ColdFusion connector directories and the Web Server webroot(s)/document root. 
# 1 if you have a user created for running Apache Services, 0 otherwise. 
APACHE_DEFAULT_USER_TRUE= 
APACHE_DEFAULT_USERNAME=apache 
APACHE_DEFAULT_GROUP= 
APACHE_DEFAULT_PASSWORD= 
 
#Enter the conf directory path of the Web Server. 
#This folder must contain the httpd.conf or apache2.conf file.Ex: /etc/apache2. 
WEBSERVER_CONF_DIR= 
 
 
#Enter the binary file path of the Web Server. Ex: /usr/sbin/apache2 
APACHE_BIN_FILE_PATH= 
 
#Enter the webroot path of the Web Server.  
#The required file system permissions will be granted to this folder.Ex; /var/www/html 
WEBROOT_PATH= 
 
#If you want to upload files to your website, specify the path of the folder where these files are to be placed.  
#This folder will also be granted write permissions. 
#Allowed: 1 if you want files to be uploaded through your website, 0 otherwise 
USER_FILE_UPLOAD_TRUE= 
USER_FILE_UPLOAD_PATH= 
 
#Enter an alias for /cf_scripts/scripts to block all calls to /cf_scripts/scripts. 
CF_SCRIPTS_ALIAS= 
 
#Allowed: 1 if you want to change the shutdown port, 0 otherwise 
CHANGE_SHUTDOWN_PORT_TRUE=1 
 
# New shutdown port number 
SHUTDOWN_PORT_NEW=

Windows - Apache

# Silent Properties file for Adobe ColdFusion Server Auto-Lockdown Installer 
# Web Server : Apache 
# Platform : Windows(All) 
 
INSTALLER_UI=SILENT 
 
#Enter the directory where ColdFusion is installed. Ex: C:\\ColdFusion2021. 
SILENT_CF_SERVER_LOCATION=C:\\ColdFusion2021 
 
#The Web Server Apache is selected for configuring the connector in ColdFusion. 
#Apache will also be locked down along with ColdFusion. 
SERVER_APACHE=1 
SERVER_IIS=0 
 
#ColdFusion Server instance intended for Lockdown Ex:cfusion 
APP_SERVER_INSTANCE= 
 
#Update ColdFusion to the latest update. Allowed : 1, if you want to update ColdFusion, 0 if not. 
UPDATE_CF_TRUE=1 
 
#Allowed : 1 for Automatic Update, 0 for Manually updating ColdFusion 
AUTO_UPDATE_CF_TRUE=1 
 
#If auto-update is false, provide the path where hotfix.jar is present. Give full path. 
HF_UPDATE_JAR_PATH= 
 
#Apache Windows 
 
#ColdFusion Configuration 
#Enter the ColdFusion Administrator credentials and the built-in Web Server port. 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT= 
 
#OS Administrator Account Details. 
#Enter the user account details of the OS administrator.  
SYSTEM_ADMIN_USER= 
SYSTEM_ADMIN_PWD= 
SYSTEM_ADMIN_DOMAIN= 
 
# Allowed :1 if you have a user already created for running CF Services, 0 otherwise. 
USER_CF_SERVICE_TRUE= 
 
# Details for User for configuring ColdFusion services and file system permissions. If not existing, a user will be created 
CF_USER_UNAME= 
CF_USER_PWD= 
CF_USER_GRP= 
 
# Enter the user account to run Web Server with, post lockdown. 
#The user account will be granted file system permissions to the ColdFusion connector directories and the Web Server webroot(s)/document root. 
# 1 if you have a user created for running Apache Services, 0 otherwise. 
APACHE_DEFAULT_USER_TRUE= 
APACHE_DEFAULT_USERNAME=apache 
APACHE_DEFAULT_GROUP= 
APACHE_DEFAULT_PASSWORD= 
 
#Enter the conf directory path of the Web Server. 
#This folder must contain the httpd.conf or apache2.conf file.Ex: C:\Apache24\conf. 
WEBSERVER_CONF_DIR= 
 
 
#Enter the binary file path of the Web Server. Ex: C:\Apache24\bin\httpd.exe 
APACHE_BIN_FILE_PATH= 
 
#Enter the webroot path of the Web Server.  
#The required file system permissions will be granted to this folder.Ex C:\Apache24\htdocs 
WEBROOT_PATH= 
 
#If you want to upload files to your website, specify the path of the folder where these files are to be placed.  
#This folder will also be granted write permissions. 
#Allowed: 1 if you want files to be uploaded through your website, 0 otherwise 
USER_FILE_UPLOAD_TRUE= 
USER_FILE_UPLOAD_PATH= 
 
#Enter an alias for /cf_scripts/scripts to block all calls to /cf_scripts/scripts. 
CF_SCRIPTS_ALIAS= 
 
#Allowed: 1 if you want to change the shutdown port, 0 otherwise 
CHANGE_SHUTDOWN_PORT_TRUE=1 
 
# New shutdown port number 
SHUTDOWN_PORT_NEW=

Windows - IIS

# Silent Properties file for Adobe ColdFusion Server Auto-Lockdown Installer 
# Web Server : IIS 
# Platform : Windows(All) 
 
INSTALLER_UI=SILENT 
 
#Enter the directory where ColdFusion is installed. Ex: C:\ColdFusion2021. 
SILENT_CF_SERVER_LOCATION= 
 
#The Web Server IIS is selected for configuring the connector in ColdFusion. 
#The IIS website(s) will also be locked down along with ColdFusion. 
SERVER_IIS=1 
SERVER_APACHE=0 
 
#ColdFusion Server instance intended for Lockdown Ex:cfusion 
APP_SERVER_INSTANCE= 
 
#Enter the IIS Website(s) you are planning to Lockdown(comma separated). Ex: site1,site2 
SILENT_WEBSITES_TO_LOCKDOWN= 
 
#Application Pool(s) for chosen website(s) (comma separated). Ex: site1AppPool,site2AppPool 
SILENT_APP_POOL_IIS_WEBSITES= 
 
#Webroot(s) folder for chosen website in IIS (comma separated) Ex: C:\inetpub\site1,C:\inetpub\site2 
SILENT_WEBROOT_IIS_WEBSITES= 
 
#Update ColdFusion to the latest update. Allowed : 1, if you want to update ColdFusion, 0 if not. 
UPDATE_CF_TRUE=1 
 
#Allowed : 1 for Automatic Update, 0 for Manually updating ColdFusion 
AUTO_UPDATE_CF_TRUE=1 
 
#If auto-update is false, provide the path where hotfix.jar is present. Give full path. 
HF_UPDATE_JAR_PATH= 
 
#ColdFusion Configuration 
#Enter the ColdFusion Administrator credentials and the built-in Web Server port. 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT= 
 
#OS Administrator Account Details. 
#Enter the user account details of the OS administrator.  
SYSTEM_ADMIN_USER= 
SYSTEM_ADMIN_PWD= 
SYSTEM_ADMIN_DOMAIN= 
 
# Allowed :1 if you have a user already created for running CF Services, 0 otherwise. 
USER_CF_SERVICE_TRUE=1 
 
#Enter the user account to run ColdFusion with, post lockdown.  
#The user account will be granted file system permissions to ColdFusion and the Web Server webroot(s)/document root. 
CF_USER_UNAME= 
CF_USER_DOMAIN= 
CF_USER_PWD= 
 
# Allowed :1 if you want to change the shutdown port, 0 otherwise 
CHANGE_SHUTDOWN_PORT_TRUE=1 
 
# New shutdown port number 
SHUTDOWN_PORT_NEW=

Windows - IIS - Uninstall properties

# Silent Properties file for Adobe ColdFusion Server Auto-Lockdown Installer 
# Web Server : IIS 
# Platform : Windows(All) 
 
INSTALLER_UI=SILENT 
 
# Enter the details for the user account that was used to configure ColdFusion during lockdown.  
# In case the user was created during the server lockdown, the user account will be deleted. 
CF_USER_UNAME_OLD= 
CF_USER_PWD_OLD= 
CF_USER_DOMAIN_OLD= 
 
# Enter the user account to run ColdFusion with post uninstallation of lockdown.  
# The given user must already exist in the system. 
CF_USER_UNAME= 
CF_USER_PWD= 
CF_USER_DOMAIN= 
 
# Enter the username, password and internal webserver port for the ColdFusion Administrator.  
# Any changes made to ColdFusion during lockdown will be reverted using these credentials. 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT=

Apache - Uninstall properties

# Silent Properties file for Adobe ColdFusion Server Auto-Lockdown Installer
# Web Server : Apache
# Platform : Windows, Solaris, Linux

INSTALLER_UI=SILENT

# Enter the details for the user account that was used to configure ColdFusion during auto-lockdown. 
# In case the user was created during the server auto-lockdown, the user account will be deleted.
CF_USER_UNAME_OLD=
CF_USER_PWD_OLD=
CF_USER_DOMAIN_OLD=

# Enter the OS user account to run ColdFusion with post uninstallation of auto-lockdown. 
# The given user must already exist in the system.
CF_USER_UNAME=
CF_USER_PWD=
CF_USER_DOMAIN=

# Enter the username, password, and internal webserver port for the ColdFusion Administrator. 
# Any changes made to ColdFusion during lockdown will be reverted using these credentials.
CF_ADMIN_USERNAME=
CF_ADMIN_PASSWORD=
CF_ADMIN_PORT=

Solaris- Silent installer properties

# Silent Properties file for Adobe ColdFusion Server Lockdown Guide Installer 
# Web Server : Apache 
# Platform : Solaris 
 
INSTALLER_UI=SILENT 
 
#ColdFusion Installation Location 
SILENT_CF_SERVER_LOCATION=/opt/coldfusion2021 
 
#Choosing Web Server 
SERVER_APACHE=1 
SERVER_IIS=0 
 
#ColdFusion Server instance intended for Lockdown 
APP_SERVER_INSTANCE=cfusion 
 
#Update ColdFusion to the latest update. Allowed : 1, if you want to update ColdFusion, 0 if not. 
UPDATE_CF_TRUE=1 
 
#Allowed : 1 for Automatic Update, 0 for Manually updating ColdFusion 
AUTO_UPDATE_CF_TRUE=1 
 
#If auto-update is false, provide the path where hotfix.jar is present. Give full path. 
HF_UPDATE_JAR_PATH= 
 
#Apache Solaris 
 
#ColdFusion Administrator details 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT= 
 
#System Admin 
SYSTEM_ADMIN_USER= 
SYSTEM_ADMIN_PWD= 
SYSTEM_ADMIN_DOMAIN= 
 
# 1 if you have a user created for running CF Services, 0 otherwise. 
USER_CF_SERVICE_TRUE= 
 
# Details for User for configuring ColdFusion services and file system permissions. If not existing, a user will be created 
CF_USER_UNAME= 
CF_USER_PWD= 
CF_USER_GRP= 
 
# Details for apache user 
# 1 if you have a user created for running Apache Services, 0 otherwise. 
APACHE_DEFAULT_USER_TRUE= 
APACHE_DEFAULT_USERNAME=apache 
APACHE_DEFAULT_GROUP= 
APACHE_DEFAULT_PASSWORD= 
 
#Apache Webroot folder path. If does not exist, one will be created. 
WEBROOT_PATH= 
 
#conf directory path for Webserver 
WEBSERVER_CONF_DIR= 
 
#Path of apache bin file 
APACHE_BIN_FILE_PATH= 
 
# 1 if you want files to be uploaded through your website, 0 otherwise 
USER_FILE_UPLOAD_TRUE= 
 
# Folder where the file upload should be allowed (inside webroot) 
USER_FILE_UPLOAD_PATH= 
 
# alias for cf_scripts 
CF_SCRIPTS_ALIAS= 
 
# 1 if you want to change the shutdown port, 0 otherwise 
CHANGE_SHUTDOWN_PORT_TRUE=1 
 
# New shutdown port number 
SHUTDOWN_PORT_NEW=

Solaris- Silent uninstaller properties

# Silent Properties file for Adobe ColdFusion Server Automated Lockdown Guide Uninstaller 
# Web Server : Apache 
# Platform : Solaris 
 
INSTALLER_UI=SILENT 
 
# New user details.  Post uninstallation, ColdFusion will run using this user. 
CF_USER_UNAME= 
CF_USER_PWD= 
# Group 
CF_USER_DOMAIN= 
 
# Old user details. This user will be deleted during uninstallation. 
CF_USER_UNAME_OLD= 
CF_USER_PWD_OLD= 
CF_USER_DOMAIN_OLD= 
 
# ColdFusion Administrator Details 
CF_ADMIN_USERNAME= 
CF_ADMIN_PASSWORD= 
CF_ADMIN_PORT=
Adobe logo

Sign in to your account