7.3 Ensure SSLv3 is disabled

Information

This protocol is not considered cryptographically secure. Disabling it is recommended.
Rationale:
Disabling weak protocols will help ensure the confidentiality and integrity of in-transit data.

Solution

Perform the following to disable SSL 3.0:
1. Set the following keyto 0.
HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server\Enabled
Default Value:
Enabled

See Also

https://workbench.cisecurity.org/files/2220

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|14.4

Plugin: Windows

Control ID: ec5b35cbfad057504e52b10668f660bef84e54dfd4d9945f8e9f12854b9eaddb