Re: Disabling SSL version 2 protocol and 40-bit and 56 bit ciphers

From: Bernard (qbernard_at_hotmail.com.discuss)
Date: 12/24/03

  • Next message: Karl Levinson [x y] mvp: "Re: mIRC virus or worm"
    Date: Wed, 24 Dec 2003 11:25:58 +0800
    
    

    Haven't tested this one, you can try -
    How to Restrict the Use of Certain Cryptographic Algorithms and Protocols in
    Schannel.dll
    http://support.microsoft.com/?id=245030

    -- 
    Regards,
    Bernard Cheah
    http://support.microsoft.com/
    Please respond to newsgroups only ...
    "Matt" <anonymous@discussions.microsoft.com> дÈëÏûÏ¢
    news:05ECEC0A-DA8E-43D0-B3FA-ED0D5FAEF660@microsoft.com...
    > I recently had a security audit on one of my web sites running IIS 5. Two
    issues were highlighted surrounding SSL:
    >
    > 1. the server supports 40-bit and 56 bit ciphers
    > 2. the SSL version 2 protocol is supported.
    >
    > I've been asked to investigate whether we can configure the server so that
    these ciphers are disabled and that only SSL version 3 and TLS are the only
    supported protocols. I can't see these options in the IIS management
    console. Is this configuration available in IIS? If not is there any way of
    implementing this? Do I need to upgrade to IIS 6?
    >
    > m@
    

  • Next message: Karl Levinson [x y] mvp: "Re: mIRC virus or worm"

    Relevant Pages

    • RE: IIS - use SSL 3.0 only
      ... SSL 3.0 for IIS 6.0 If I am off base, please don't hesitate to let me know. ... Microsoft is providing this information as a convenience to you. ... If the server and the client have multiple protocols in common, ...
      (microsoft.public.windows.server.sbs)
    • Re: SSL broken after Windows 2003 upgrade
      ... The svchost.exe you reference is "IIS". ... routes them to the appropriate w3wp.exe based on configuration from WAS ... WFetch can make both a normal SSL request as well as a Client-Certificate ...
      (microsoft.public.inetserver.iis)
    • Re: Win2003 Upgrade Broke SSL?
      ... The reason I say that the upgrade did not break SSL is because IIS has no ... problems relating to port 443 being occupied suggests that you did something ...
      (microsoft.public.inetserver.iis)
    • Re: WCF webservice over SSL and without
      ... Based on your further description, you have setup the SSL correctly in IIS server, but encountered some problem visit the WCF service's metadata page, correct? ... \par> Microsoft MSDN Online Support Lead ...
      (microsoft.public.dotnet.framework.webservices)
    • Re: ** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.08.15
      ... Here's how to enable SSL in IIS 5.0, not sure if 5.1 is different. ... XP comes with a different mini-IIS MMC that is confusing to me and does not ... Regarding your cert question, you have a choice of using the test cert from ...
      (microsoft.public.inetserver.iis.security)