While I am not sure I buy into the assumption that this is more secure, it will do exactly what they want. So, yes, CF can do, and has done it for years.
--- Ben My assumption is that the thinking is that one can expose only a static site with no dynamic capability to the whole wide world. Then your application server is configure in a more secure DMZ or something and restricted to accept direct requests only from the web server. Thus limiting the exposure of the system that potentially has more capability to do more damage. How true this assumption is in either theory and|or practice I can not speak. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Check out the new features and enhancements in the latest product release - download the "What's New PDF" now http://download.macromedia.com/pub/labs/coldfusion/cf8_beta_whatsnew_052907.pdf Archive: http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:289347 Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4

