16.04.2013 Views

Adobe® ColdFusion® 10 Server Lockdown Guide

Adobe® ColdFusion® 10 Server Lockdown Guide

Adobe® ColdFusion® 10 Server Lockdown Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The IIS Application Pool user (iisservice in our examples) must also have permission access the Tomcat IIS<br />

connector. Grant this user permission to the \config\wsconfig\ directory in your ColdFusion installation<br />

directory.<br />

Folder Permission<br />

{coldfusion-home} Full Control<br />

{coldfusion-home} Full Control<br />

{coldfusion-home}/config/wsconfig/ • List folder / read<br />

data<br />

• Read attributes<br />

• Read extended<br />

attributes<br />

• Read permissions<br />

{coldfusion-home}/cfusion/wwwroot/CFIDE • List folder / read<br />

data<br />

• Read attributes<br />

• Read extended<br />

attributes<br />

• Read permissions<br />

The ColdFusion IIS connector writes logs to a file called isapi_redirect.log - the IIS Application Pool<br />

user (iisservice in our example) needs write permission to this file. You may consider changing the location of<br />

this file, which is defined in the isapi_redirect.properties file to a directory elsewhere.<br />

Note: if you choose to run Anonymous Authentication through the Application Pool user then IUSR does not<br />

need permission to these files.<br />

Note: if you are setting up multiple instances of ColdFusion or multiple connectors you will need to repeat this<br />

step for each connector. Each connector instance is placed in a subdirectory of {coldfusionhome}/config/wsconfig/<br />

with a number (starting with 1 by default).<br />

42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!