{"id":26,"date":"2010-06-22T16:36:09","date_gmt":"2010-06-22T20:36:09","guid":{"rendered":"http:\/\/www.amixa.com\/blog\/?p=26"},"modified":"2010-06-22T16:39:01","modified_gmt":"2010-06-22T20:39:01","slug":"ssl-weak-encryption-algorithms-how-to-disable-them-under-iis","status":"publish","type":"post","link":"https:\/\/www.amixa.com\/blog\/2010\/06\/22\/ssl-weak-encryption-algorithms-how-to-disable-them-under-iis\/","title":{"rendered":"SSL Weak Encryption Algorithms &#8211; how to disable them under IIS"},"content":{"rendered":"<p>Chances are if you are reading this you&#8217;ve failed a &#8220;Trustkeeper Scan&#8221; &#8211; with\u00a0&#8220;Low severity&#8221; &#8211; due to having weak SSL encryption algorithms enabled on IIS.<\/p>\n<p>It&#8217;s pretty easy to solve this, <a href=\"http:\/\/support.microsoft.com\/kb\/245030\" target=\"_blank\">but if you read the microsoft KB article<\/a> it looks pretty complicated.<\/p>\n<p>Launch regedit and go to this key:<\/p>\n<pre><span style=\"color: #ff6600;\"><strong>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Ciphers<\/strong><\/span><\/pre>\n<p>You basically want to disable everything that has less than 128 bit encryption.\u00a0 On one of my servers, the ones with red arrows below need to be disabled:<\/p>\n<div id=\"attachment_27\" style=\"width: 310px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/6-22-2010-4-30-35-PM.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-27\" class=\"size-medium wp-image-27\" title=\"Weak encryption algorithms\" src=\"http:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/6-22-2010-4-30-35-PM-300x116.png\" alt=\"CLICK FOR LARGER IMAGE\" width=\"300\" height=\"116\" srcset=\"https:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/6-22-2010-4-30-35-PM-300x116.png 300w, https:\/\/www.amixa.com\/blog\/wp-content\/uploads\/2010\/06\/6-22-2010-4-30-35-PM.png 554w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-27\" class=\"wp-caption-text\">CLICK FOR LARGER IMAGE<\/p><\/div>\n<p>So on each one of these, you want to &#8220;Right click&#8221;, add a DWORD, name it &#8220;Enabled&#8221; and set the Hex value to 00000000\u00a0 (eight zeros).<\/p>\n<p>Repeat for each one that has less than 128 bit length, and then restart your server.<\/p>\n<p>You probably also need to reschedule a security scan so that your changes can be verified, and as always, please double check your SSL protected site with at least two different web browsers and make sure you can get into SSL mode with them both on your site.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chances are if you are reading this you&#8217;ve failed a &#8220;Trustkeeper Scan&#8221; &#8211; with\u00a0&#8220;Low severity&#8221; &#8211; due to having weak SSL encryption algorithms enabled on IIS. It&#8217;s pretty easy to solve this, but if you read the microsoft KB article it looks pretty complicated. Launch regedit and go to this key: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Ciphers You basically want to disable everything that has<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[7,5,8,101,9],"class_list":["post-26","post","type-post","status-publish","format-standard","hentry","category-random-bits","tag-encryption","tag-iis","tag-microsoft-windows-server","tag-ssl","tag-trustkeeper-scan"],"_links":{"self":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/26","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/comments?post=26"}],"version-history":[{"count":4,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/26\/revisions"}],"predecessor-version":[{"id":32,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/posts\/26\/revisions\/32"}],"wp:attachment":[{"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/media?parent=26"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/categories?post=26"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.amixa.com\/blog\/wp-json\/wp\/v2\/tags?post=26"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}