Copy link to clipboard
Copied
Here is the log file - The RDP is not enabled but the error says it is and it is a Production install with security: --- Any Thoughts on getting this lockdown tool to work?
2025-03-08 22:31:41 INFO - Path:C:\ColdFusion2023\lockdown\cfusion
2025-03-08 22:31:41 INFO - LINE_DEBUGGER_ENABLED -> false
2025-03-08 22:31:41 INFO - developer_enabled -> false
2025-03-08 22:31:41 INFO - REMOTE_INSPECTION_ENABLED -> false
2025-03-08 22:31:41 INFO - ajax_enabled -> false
2025-03-08 22:31:41 INFO - robust_enabled -> false
2025-03-08 22:31:41 INFO - FLASHFORMCOMPILEERRORS -> false
2025-03-08 22:31:41 INFO - enabled -> false
2025-03-08 22:31:41 INFO - Remote admin component is enabled. Server is not production profile. Please delete the AdminServlet.war from jetty to disable it and try again!
2025-03-08 22:31:43 INFO - ColdFusion is running
To get the lockdown tool to work I did as the log file said... - "Remote admin component is enabled. Server is not production profile. Please delete the AdminServlet.war from jetty to disable it and try again."
i deleted the AdminServlet.war file.
Once i installed the tool, the permissions on the other website (.net) on the server were completely hosed, even though i did not select it as one of the sites. And, the install of ColdFusion Admin was not accessible and neither were any websites runnin
...Copy link to clipboard
Copied
I got it... thanks
Copy link to clipboard
Copied
Hi @LarryRamp , glad to hear that you solved it. Could you please share your solution with the rest of the forum? It will certainly help someone somewhere.
Copy link to clipboard
Copied
While we await his reply, I'll note that the error log does say it was NOT running the production profile, as Larry proposed. It will be interesting to hear which it was.
BTW, Larry, the "remote admin" referred to is not about "RDP" but about an option offered during the CF install process (on its "servlets" page, along with solr and pdfg), which if enabled get implemented in the cf add-on service (the "jetty" mentioned there). It's a feature which primarily allows start/stop of cf from CFBuilder, so not desired or needed in the prod profile. Not critical to know, but just thought you or future readers might appreciate the clarification.
Copy link to clipboard
Copied
To get the lockdown tool to work I did as the log file said... - "Remote admin component is enabled. Server is not production profile. Please delete the AdminServlet.war from jetty to disable it and try again."
i deleted the AdminServlet.war file.
Once i installed the tool, the permissions on the other website (.net) on the server were completely hosed, even though i did not select it as one of the sites. And, the install of ColdFusion Admin was not accessible and neither were any websites running CF. I did select IIS when the i went thru the lockdown tool install... at this point i was thinking ... restart CF web service? The tool turned all the CF services off, when i trued to start the CF web service, if would not start. Fortunately i took a full backup prior to installing the lockdown tool. I did a restore of the server and called it a night.
Today i will attempt this process again. Any thoughts or insights?
Copy link to clipboard
Copied
Thanks for sharing that, @LarryRamp .