7.4 Ensure TLS 1.0 is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The PCI Data Security Standard 3.1 recommends disabling 'early TLS' along with SSL:
SSL and early TLS are not considered strong cryptography and cannot be used as a security control after June 30, 2016.
Rationale:
This item is Not Scored for the following reasons:
* Enabling TLS 1.2 is recommended.
* These protocols do not suffer from known practical attacks.

Solution

Set the following registry locations to configure TLS 1.0. To disable, set Enabled to 0.
HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server\Enabled

See Also

https://workbench.cisecurity.org/files/2220

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8, CSCv7|14.4

Plugin: Windows

Control ID: b0566c1f4cfd9c4268e260485039ffd98a07a108174e20b6815de82c7b8b3a07