7.5 Ensure TLS 1.1 is enabled

Information

Enabling TLS 1.1 is required for backward compatibility.

Rationale:

This item is Not Scored for the following reasons:

Enabling TLS 1.2 is recommended.

This protocol does not suffer from known practical attacks.

Solution

Set the following registry locations to enable TLS 1.1. Set Enabled to 1.

HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server\Enabled

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: d2172140cdd6f5b3d2a07015ef56db182069d1bd20fb1a6eb27b7ae7b6880722