{"id":18,"date":"2010-06-22T16:16:11","date_gmt":"2010-06-22T20:16:11","guid":{"rendered":"http:\/\/www.amixa.com\/blog\/?p=18"},"modified":"2013-10-26T17:15:37","modified_gmt":"2013-10-26T21:15:37","slug":"disabling-sslv2-support-in-iis","status":"publish","type":"post","link":"https:\/\/www.amixa.com\/blog\/2010\/06\/22\/disabling-sslv2-support-in-iis\/","title":{"rendered":"Disabling SSLv2 support in IIS"},"content":{"rendered":"<h4>If you have undergone a &#8220;Trustkeeper Scan&#8221; and failed due to your Microsoft web server using SSLv2, then read on.<\/h4>\n<p><span style=\"color: #ff0000;\">NOTE: <a href=\"http:\/\/www.amixa.com\/blog\/2012\/12\/22\/how-to-get-iis-7-5-web-server-to-pass-the-beast-pci-vulnerability-compliance-scans\/\">PLEASE READ THIS POST IN OUR BLOG HERE<\/a>.\u00a0 It is TWO YEARS NEWER and simplifies most of the tasks regarding SSL settings.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>SSLv2 is considered a &#8220;medium&#8221; security risk and will cause your scan to FAIL, so therefore to be PCI-DSS compliant (for credit card companies), you need to disable it via the registry on your Windows server running IIS 3 or later.<\/p>\n<p>The easiest way to do this is to <a href=\"http:\/\/support.microsoft.com\/kb\/187498\" target=\"_blank\">read this KB article from Microsoft<\/a>.<\/p>\n<p>In a nutshell, you need to go to this registry key<\/p>\n<pre><span style=\"color: #ff6600;\"><strong>HKey_Local_Machine\\System\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols<\/strong><\/span><\/pre>\n<p>Then locate the SSL 2.0 key<br \/>\n<a href=\"http:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/7-15-2010-2-26-31-PM.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-79\" title=\"Disable SSLv2\" alt=\"\" src=\"http:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/7-15-2010-2-26-31-PM.jpg\" width=\"472\" height=\"210\" srcset=\"https:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/7-15-2010-2-26-31-PM.jpg 472w, https:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/7-15-2010-2-26-31-PM-300x133.jpg 300w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/a><\/p>\n<ul>\n<li>Click on the &#8220;Server&#8221; node.<\/li>\n<li>On the <strong>Edit<\/strong> menu, click <strong>Add Value<\/strong>.<\/li>\n<li>In the <strong>Data Type<\/strong> list, click <strong>DWORD<\/strong>.<\/li>\n<li>In the <strong>Value Name<\/strong> box, type <span style=\"color: #ff0000;\"><strong>Enabled<\/strong><\/span>, and then click <strong>OK<\/strong>.\u00a0 <strong>Note:<\/strong> If this value is present, just double-click the value to edit its current value.<\/li>\n<li>Type <strong>00000000<\/strong> in Binary Editor to set the value of the new key equal to &#8220;0&#8221;.<\/li>\n<li>Click <strong>OK<\/strong>. Restart the computer<\/li>\n<li>if applicable, reschedule the security scan<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>If you have undergone a &#8220;Trustkeeper Scan&#8221; and failed due to your Microsoft web server using SSLv2, then read on. NOTE: PLEASE READ THIS POST IN OUR BLOG HERE.\u00a0 It is TWO YEARS NEWER and simplifies most of the tasks regarding SSL settings. &nbsp; SSLv2 is considered a &#8220;medium&#8221; security risk and will cause your scan to FAIL, so therefore<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[7,5,8,101,10,9],"class_list":["post-18","post","type-post","status-publish","format-standard","hentry","category-iis-tips-n-tricks","tag-encryption","tag-iis","tag-microsoft-windows-server","tag-ssl","tag-sslv2","tag-trustkeeper-scan"],"_links":{"self":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/18","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/comments?post=18"}],"version-history":[{"count":12,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/18\/revisions"}],"predecessor-version":[{"id":299,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/18\/revisions\/299"}],"wp:attachment":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/media?parent=18"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/categories?post=18"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/tags?post=18"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}