CF10 and File Extensions Request Filtering
there organizations disa/dod require when using iis 7/7.5/8 set request filtering -> file name extensions -> edit features settings -> allow unlisted file name extensions disabled. forces add every single file extension type needed allow entry in file names extensions section them run. wanted make post because it's easy miss 1 of items required result in system not functioning expected. there several obvious ones without them allowed cfide not load @ all. if miss .js item run issues. system continuously inform password invalid when not. unlike of others lack of .js not show visually except menu items pre-colapsed , can't login via username/password making have bypass security.
here list of items needed cfide running under locked down scenario.
- . (just period itself, required allow default documents load)
- .cfc
- .cfm
- .dll
- .gif
- .jpg
- .js
interesting tip. sharing.
/charlie
More discussions in ColdFusion Server Administration
adobe
Comments
Post a Comment