RE: [ACFUG Discuss] CF Service Account

2007-08-02 Thread Charlie Arehart
hen discussing locking down CF servers. /charlie -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Mason Sent: Wednesday, August 01, 2007 4:58 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account The issue, as I remember, is ho

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
ion and Flex hosting Now offering ColdFusion 8 Enterprise hosting FREE Subversion hosting -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rob Saxon Sent: Wednesday, August 01, 2007 5:01 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Ac

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
n Behalf Of Rob Saxon Sent: Wednesday, August 01, 2007 5:01 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account Is there a document or web site with CF security best practices? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of John Maso

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
urity best practices? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of John Mason Sent: Wednesday, August 01, 2007 4:58 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account The issue, as I remember, is how Jrun implements JAAS. Lib i

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Rob Saxon
Is there a document or web site with CF security best practices? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of John Mason Sent: Wednesday, August 01, 2007 4:58 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account The issue, as I

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
r site and server John [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Wednesday, August 01, 2007 4:36 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account If you are using sandbox security, w

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Wednesday, August 01, 2007 3:32 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account Well the point is really you can't secure what you don't know about. CF can be a very secure platform if you know how to secure

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
[mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Wednesday, August 01, 2007 3:32 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account Well the point is really you can't secure what you don't know about. CF can be a very secure platform if you know how to secure

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
ng Now offering ColdFusion 8 Enterprise hosting FREE Subversion hosting From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Wednesday, August 01, 2007 3:17 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account Sandbox security is

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Kevin
e hosting > FREE Subversion hosting > > > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe > Sent: Wednesday, August 01, 2007 3:17 PM > To: discussion@acfug.org > Subject: Re: [ACFUG Discuss] CF Service Account > > San

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
ean H. Saxe Sent: Wednesday, August 01, 2007 3:17 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account Sandbox security is fine when it is backed up by OS-level security. What hack do you refer to? That's a new one on me. -dhs Dean H. Saxe, CISSP, CEH [EMAIL PROT

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
On Behalf Of Dean H. Saxe Sent: Wednesday, August 01, 2007 3:17 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account Sandbox security is fine when it is backed up by OS-level security. What hack do you refer to? That's a new one on me. -dhs Dean H. Saxe, C

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
o:[EMAIL PROTECTED] On Behalf Of Charlie Arehart Sent: Wednesday, August 01, 2007 2:59 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account No value in the resource/sandbox security? :-) /charlie From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rob

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
t Sent: Wednesday, August 01, 2007 2:59 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account No value in the resource/sandbox security? :-) /charlie _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rob Saxon Sent: Wednesday, August 01, 2007 2:05

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Charlie Arehart
No value in the resource/sandbox security? :-) /charlie _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rob Saxon Sent: Wednesday, August 01, 2007 2:05 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account Thank you John and Dean for your

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
, August 01, 2007 2:05 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account Thank you John and Dean for your feedback. The CF script needs to write the contents of a web form to a folder on another server so that an application on that server can read in the f

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Rob Saxon
Sent: Wednesday, August 01, 2007 1:50 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] CF Service Account Dean said it and I completely agree. Be very careful not to use the default local system account for this or on a AD account. A web app really doesn't need high level permission

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread John Mason
usionlink.com/> - ColdFusion and Flex hosting Now offering ColdFusion 8 Enterprise hosting FREE Subversion hosting _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rob Saxon Sent: Wednesday, August 01, 2007 12:22 PM To: discussion@acfug.org Subject: [ACFUG Discuss] CF Serv

RE: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Charlie Arehart
Wednesday, August 01, 2007 12:25 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] CF Service Account CF should never be run as a high privileged account. Create a low privilege account and run CF under that account. Only allow CF permissions on the filesystem where they are absolutel

Re: [ACFUG Discuss] CF Service Account

2007-08-01 Thread Dean H. Saxe
CF should never be run as a high privileged account. Create a low privilege account and run CF under that account. Only allow CF permissions on the filesystem where they are absolutely required. Ensure CF does not have any administrative privileges if they are not used (like using to ed

[ACFUG Discuss] CF Service Account

2007-08-01 Thread Rob Saxon
By default the CF service runs as a System account. What is the best practice to allow this service to access all areas of the web server and other server shares? Here are some ideas I considered: Scenario 1: Creating a domain account for the service with that belongs to the local Admin group fo