Status/Resolution/Reason: Closed/Fixed/
Reporter/Name(from Bugbase): David Epler / David Epler (David Epler)
Created: 03/25/2013
Components: Installation/Config
Versions: 10.0
Failure Type: Enhancement Request
Found In Build/Fixed In Build: Final / 288700,288699
Priority/Frequency: Trivial / Unknown
Locale/System: English / Platforms All
Vote Count: 1
Duplicate ID: CF-3590046
The ColdFusion 10 installer set Secure Profile to be an opt-in with it being shown as "Enable Secure Profile". This should be changed to make it an opt-out with "Disable Secure Profile".
Too many admins just click through the installer. Changing it would result in deployment of more secure ColdFusion installs. While there might be an inconvenience to roll back some of the settings, the recent attacks show that Secure Profile should be the default and not an option.
----------------------------- Additional Watson Details -----------------------------
Watson Bug ID: 3529334
External Customer Info:
External Company:
External Customer Name: David Epler
External Customer Email:
Attachments:
Comments: