Entries Tagged as “ColdFusion Secure Profile”
Security | Adobe ColdFusion 10 | Application Server | ColdFusion Secure Profile | web application security
About Secure Profile
In ColdFusion 10, the “Secure Profile” feature was added. It can be enabled at the time of installation and helps configure some of the important settings for securing server. It is highly recommended to choose this option for production servers. Complete details of Secure Profile can be found here.
Determining the status of Secure Profile
Once you enable this option from Installer, there are multiple ways to determine the status of “Secure Profile”.
- In <ColdFusion-home>/lib/neo-security.xml, “secureprofile.enabled” flag value indicates if secure profile is enabled or not. Note: Changing value of this flag post installation will not re-configure other secure profile affected settings.
- Alternatively you can use Admin Extension created by Raymond Camden. Details can be found here.
- You can also check in web.xml file under runtime/conf. There is a section (“<!—secure profile enable start” ) that will be commented out if it is not turned on.