7.12 Ensure AES 128/128 Cipher Suite is configured

Information

Enabling AES 128/128 may be required for client compatibility. Enable or disable this cipher suite accordingly.

Rationale:

This item is Not Scored for the following reasons:

Enabling AES 256/256 is recommended.

This cipher does not suffer from known practical attacks.

Solution

To enable the AES 128/128 cipher, ensure the following key is set to 0xFFFFFFFF:

HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\AES 128/128\Enabled

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 2c5fcef99ba3a09fee02bf16c22c32b5a91634d5fb24bb5b4aeaafed9dff4429