Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

ColdFusion 2025 Auto-Lockdown

Explorer ,
Oct 20, 2025 Oct 20, 2025

I am trying to run the ColdFusion 2025 Auto-Lockdown on ColdFusion Update 4.

 

At first it was failing with the following error in the application log: Function getAdminSettings does not support adminpassword as an argument in ...CFIDE\lockdown\lockdown.cfc.

 

I read on the Update 2 page (https://helpx.adobe.com/coldfusion/kb/coldfusion-2025-update-2.html), If you want to apply lockdown on this update, add the -Dcoldfusion.runtime.remotemethod.matchArguments flag. So I did that.

 

Now I am getting a new error: The USERNAME parameter to the getAdminSettings function is required but was not passed in.

 

Are there any other modification or jvm flags I need to add to run the auto-lockdown? Thank you.

123
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines

correct answers 1 Correct answer

Explorer , 5 hours ago 5 hours ago

After speaking with CF support, it turns out that the Lockdown tool cannot be executed again once it has already been applied, until you uninstall the previously applied Lockdown.

 

You can uninstall the Lockdown tool by running the uninstall.exe file located at the path below:

<ColdFusion202X>\lockdown\cfusion\uninstall

 

After doing this, the instance was found the next time I ran the Lockdown tool.

Translate
Explorer ,
Oct 20, 2025 Oct 20, 2025

This is resolved. Received a new lockdown.cfc directly from Adobe and it works now.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Oct 20, 2025 Oct 20, 2025

Roberto, while you later clarify that Adobe gave you an updated cfc, can you confirm something for future readers here? You say you "did that", regarding the technote directive to "add the -Dcoldfusion.runtime.remotemethod.matchArguments flag", but it didn't help.

 

Did you see that to true or false? Or did you perhaps assign no value? It should have been set to false, though that technote does not clarify it. 


/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Oct 20, 2025 Oct 20, 2025

Charlie, good catch. I literally copied -Dcoldfusion.runtime.remotemethod.matchArguments and didn't even notice it was set to no value. My mistake. That being said, after contacting CF support, I was given a new lockdown.cfc file that just worked.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Oct 20, 2025 Oct 20, 2025

Thanks, and yep, the new cfc would have been modified to define all incoming args for any remote methods--which broke once the update came out that required that. They just hadn't thought to tweak that code before releasing the update.

 

Again, that update technote needs to be made more clear. It would be nice if someone from Adobe might see this and agree (given Roberto's acknowledgment of what I've feared.)

 

Anyway, thanks for confirming. Hope it may help others. 


/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Oct 20, 2025 Oct 20, 2025

I went ahead and filed a bug report on this issue with the update technote. It could help if readers here would add a vote:

 

https://tracker.adobe.com/#/view/CF-4228385


/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Oct 21, 2025 Oct 21, 2025

Thanks Charlie. I added a vote. As you mentioned in the bug report, it is from 2 updates ago, but I have several clients moving to CF 2025 right now (with CF 2021 support ending in a few weeks) and the auto-lockdown issue will occur for others that are making the upgrade right now (so the technotes should be clear). Thanks again for pointing out the issue!

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Oct 21, 2025 Oct 21, 2025

Yep, agreed on the continued importance of even an older technote. 

 

And as you may have been notified since having voted, they have indeed now fixed the problem--updating the update technotes from May 2025 for all 3 versions: cf2025, 2023, and 2021. 🙂 

 

As I just said there, thanks to Adobe for taking care of this so quickly. I appreciate that even such a simple fix can often fall behind in a large pile of to do's. And let this encourage others to take the time to report issues. 


/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
14 hours ago 14 hours ago

Charlie, while we are on the topic of the auto-lockdown, have you ever encountered the following issue? I successfully ran the 2025 Auto-Lockdown on ColdFusion Update 4. If I now try to rerun the tool, I get an error that states "No ColdFusion instance(s) available to lock down" (image uploaded). ColdFusion is running fine and I see no errors in the log files. Why would it not see the instance now?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
13 hours ago 13 hours ago

I am not sure. Perhaps someone else will chime in, or ask Adobe via that same cfsup address (and share the answer here). In the meantime, here are some ideas:

  • It may well simply be that once you've run it on an instance (of a given version and update) you can't run it again. Anyone know?
  • There are various prerequisites to be able to run it. Perhaps one of them have changed since you previously did. See the install doc page for the tool, and search for "pre-requisite" (note the dash). See the box following that also
  • When you say you checked the logs, do you mean those in the special "lockdown" folder, created by the tool and discussed on that doc page? 

/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
13 hours ago 13 hours ago

I reached out to Adobe yesterday. Will follow up when I have more info. I checked the the CF logs and lockdown logs and prerequisites. I am thinking the same as you, that maybe once it is run on a given update it cannot be run again. That would imply that there is a flag somewhere that is preventing it. Will keep you posted. Thanks!

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
5 hours ago 5 hours ago
LATEST

After speaking with CF support, it turns out that the Lockdown tool cannot be executed again once it has already been applied, until you uninstall the previously applied Lockdown.

 

You can uninstall the Lockdown tool by running the uninstall.exe file located at the path below:

<ColdFusion202X>\lockdown\cfusion\uninstall

 

After doing this, the instance was found the next time I ran the Lockdown tool.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources