System information
Adobe documentation - Confidential 
Contents 
Introduction .................................................................................................................................................. 6 
Default File Paths and Usernames ............................................................................................................ 6 
Operating Systems and Web Servers ........................................................................................................ 6 
ColdFusion Version ................................................................................................................................... 6 
Scope of Document ................................................................................................................................... 6 
Applying to Existing Installations .............................................................................................................. 6 
Naming Conventions ................................................................................................................................. 6 
ColdFusion on Windows ........................................................................................................................... 7 
Installation Prerequisites .......................................................................................................................... 7 
ColdFusion Installation .............................................................................................................................. 7 
Install ColdFusion Hotfixes and Updates ................................................................................................ 13 
Create User Accounts .............................................................................................................................. 14 
Setup Permissions for ColdFusion User .................................................................................................. 16 
Registry Permissions ........................................................................................................................... 18 
Specify Log On User for ColdFusion Services .......................................................................................... 20 
Setup Web Root Folder Structure ........................................................................................................... 20 
Setup Web Root Permissions .................................................................................................................. 22 
Table 2.8.1 Web Root Content Security Permissions ......................................................................... 22 
Add Required IIS Roles & Role Services .................................................................................................. 24 
Configure IIS ............................................................................................................................................ 26 
Configure Request Filtering ................................................................................................................ 26 
Table 2.10.1 : CFIDE URIs .................................................................................................................... 27 
Table 2.10.2: Additional URIs to consider blocking: ........................................................................... 29 
Configure Application Pool Defaults ................................................................................................... 31 
Remove X-Powered-By Response Header .......................................................................................... 31 
Remove ASP.NET ISAPI Filters ............................................................................................................. 31 
Create ColdFusion Administrator Web Site ............................................................................................ 32 
Remove Request Filtering Rule for ColdFusion Administrator Site .................................................... 33 
Add Sites to IIS ........................................................................................................................................ 34 
Adobe documentation - Confidential 










