• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
0

Enterprise License key activation on AWS

Explorer ,
Dec 04, 2023 Dec 04, 2023

Copy link to clipboard

Copied

For PCI compliance reasons we need to restrict outbound access on some CF servers. From the license.log we can see that the domain required for activation is adobe.coldfusion.io . That's fine when internet access is enabled. What we would like to do (in AWS) is to effectively whitelist this 'domain' but AWS will  only accept IP addresses, and as far as we can tell this domain uses dynamic IP's. Clearly this can all be worked around by our DevOps guys as and when required , but ideally we would have IAC code to handle this automatically so that newly built AMI servers do not require a manual patch to temporarily allow internet access to activation and then close it down, i.e. we would like a more 'permanent' solution.

So the questions to the Adobe community: is there a known range of License activation IP's we could rely on (without having to do reverse lookup and figure it out on-the-fly) ? 

Or, has anyone else using AWS internet restricted serves encountered this and found an alternative  solution ? Many thanks in advance.

Views

176

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Dec 04, 2023 Dec 04, 2023

Copy link to clipboard

Copied

While you await a good answer to that question,. I'll point out for you and others that there's no discussion of this (ip addresses) in the substantial Adobe doc page on licensing and activation at https://helpx.adobe.com/coldfusion/using/coldfusion-licensing-activation.html, including if all the collapsed sections are expanded.

 

Once there is an answer identified here, I hope it would be offered on that page, at least for the sake of people who might look to that rather than find this in the forums. (Who knows which on. e search engines may favor, also.) 


/Charlie (troubleshooter, carehart.org)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Jan 11, 2024 Jan 11, 2024

Copy link to clipboard

Copied

There has been no answer from Adobe on this so far. Has no-one ever had to whitelist outpund IP address range for activation server coldfusion.abobe.io  from a cloud environment like AWS  ? Or for that matter https://www.adobe.com/go/coldfusion-updates for updates ?

Appreciate this would not be an issue if AWS allowed a domain name whitelist but we have been informed that this is not possible i.e. has to be physical IP address or range. But right now we belive this isn't possible.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 11, 2024 Jan 11, 2024

Copy link to clipboard

Copied

Bill, it's not necessarily that "no one" has faced the situation. First, they may have solved it differently than the specific solution you seek. :-)

 

Have you confirmed that your aws setup does NOT allow configuring a proxy (allowing outbound access)? Note that's supported by cf, and was offered first with the updates feature (via the settings tab on its page). Now they leverage that also for the activation feature as added in cf2021. And as you may know, such a proxy need not allow ALL outbound access but can be limited to allow only some domains. Let us know if you've considered that. 

 

Assuming it can't work for you, then back to your plea, let's note (second) that the number of people HERE who run production on aws and might offer a solution may indeed be limited. Not limited because few use cf in prod on aws, but because already it's only a tiny subset of people using cf who *follow these threads to offer answers*. I'm not saying many don't see these threads: I'm saying few follow EVERY new thread, thus reducing the number of people--even before wondering a) how many offer answers at all and b) how many may have THAT specific answer you seek. 🙂 

 

What can you do, to reach a wider audience? There may be an answer, and as you may know there ARE other places to raise the question--and some are better suited to thr hope of many people seeing each NEW post, or bringing that to people's attention as others reply. I list such alternatives at https://cf411.com/cfcommhelp

 

You could point them here for context (and in case it may help them avoid raising ideas raised here). Better still, if you may solve the problem, please do share it here or at least point to where it may end up being discussed.

 

Or perhaps Adobe or someone WILL now see this and offer an answer here. 🙂 


/Charlie (troubleshooter, carehart.org)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Jan 11, 2024 Jan 11, 2024

Copy link to clipboard

Copied

Charlie,

 

As always v.helpful input - yes my question was a bit of a cry in the darkness I suppose ("is there anybody out there" :0). All you say is valid. I will certainly take the proxy idea forward as no, we haven't tried that yet.

 

My problem partly with this issue is that I'm hunting around for a solution to something I have limited access/understanding of, and a bit uncertain of asking the right question, but we live and learn. I think I get the idea of a Licensing and Update proxy server for CF, and will try to gen up on that. Will also poke around in other forums that you point out.

 

Certainly will share here when/if we find a solution and look around in more places via your link.

 

I believe we are also continuing to look into AWS domain whitelisting. It seems odd to me that this not readily available as an AWS feature, but there are no doubt valid reasons why not.

 

Thanks,

 

Bill

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 11, 2024 Jan 11, 2024

Copy link to clipboard

Copied

Great to hear and thanks for the update. 


/Charlie (troubleshooter, carehart.org)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 11, 2024 Jan 11, 2024

Copy link to clipboard

Copied

LATEST

This isn't really a question for Adobe, but rather for Amazon. It appears to be possible, if you purchase additional AWS gizmos like AWS Network Firewall:

 

https://docs.aws.amazon.com/network-firewall/latest/developerguide/stateful-rule-groups-domain-names...

 

I've at best skimmed that link, but it appears that you may be able to do what you want with some AWS knowledge.

 

Dave Watts, Eidolon LLC

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources
Documentation