7.3 Ensure SSLv3 is disabled

Information

This protocol is not considered cryptographically secure. Disabling it is recommended.

Rationale:

Disabling weak protocols will help ensure the confidentiality and integrity of in-transit data.

Solution

Perform the following to disable SSL 3.0:
1. Set the following keyto 0.

HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server\Enabled

Default Value:

Enabled

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 45d14f56d2d64d25bfb0ba979498d0bde9d30314e3bfc5d5f59b20c059380262