Solved

Coldfusion code looking for CGI.https_keysize lt 128 and Blocking the user

Posted on 2012-12-21
3
359 Views
Last Modified: 2012-12-27
Hello Experts,

CF Code is looking for CGI. https_keysize variable and does an abort when its lt 128.

<cfif CGI.https_keysize LT 128>
      We will only allow 128-bit encrypted connection between your machine and our web site.  
Your Internet browser is not able to support High Encryption, please contact your Helpdesk or System Administrator to apply 128-bit Encryption Pack on your Internet browser.

      <cfabort>
</cfif>

I have this application running on IIS , but its not https in the URL.
HTTPS_KEYSIZE [empty string]  is empty as I dump the cgi variable

I am unaware how to resolve this issue, Do I need to something for the cg.https_keysize to return some value.?
0
Comment
Question by:Dan_Schimo
  • 2
3 Comments
 
LVL 36

Expert Comment

by:SidFishes
ID: 38713727
I'm confused by this

"I have this application running on IIS , but its not https in the URL.
HTTPS_KEYSIZE [empty string]  is empty as I dump the cgi variable"

CGI variables are only valid for the current request. If it's not https in the url, you won't get an https_keysize value.
0
 

Author Comment

by:Dan_Schimo
ID: 38713794
Thank you for your input SidFishes . This code was running on some server, before it came to me. Yes, previously they had https: in the URL. Can you please let me know how to get the Https in the URL on this Current server.

CF 10
Local Box xp
IIS 5.1

site is currently running on localhost 127.0.0.1
0
 
LVL 36

Accepted Solution

by:
SidFishes earned 500 total points
ID: 38713880
Well, that really should be another question but since it's the holidays....

You need an SSL certificate. You can buy one from verisign, godaddy, digicert and others.
or you can generate your own if this is for intranet use (local network only)

Self signed certs on iis5.1
http://huntjason.wordpress.com/2007/03/27/generating-self-signed-certificates-to-enable-ssl-https-on-iis-5-1-windows-xp-professional/

Then follow these steps.
http://www.codeproject.com/Articles/56958/Securing-My-Website-Using-SSL-in-Local-IIS-5-1-and

If you need more help than what those links provide, you'll need to start a new question as this one is answered. (A: you can't use cgi.https_keysize without SSL)
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

PROBLEM:  How to open a cfwindow or run a function on double click of a cfgrid row. One of my clients wanted to be able to double click on a row item to get more detailed information about a transaction and to be able to modify the line items i…
Recently while working on a project I got a very annoying cfdocument has no body error message. I had never seen this error before. So I checked the code. The code was pretty simple; it was Just showing me the cfdocumnt tag and inside that tag a …
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question