1.2.7 Configure SSL for Basic Authentication

Information

Credentials sent in clear text can be easily intercepted by malicious code or persons. Enforcing the use of Secure Sockets Layer will help mitigate the chances of hijacked credentials.

NOTE : Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

To Use Basic Authentication with SSL: Open IIS Manager In the Connections pane on the left, select the server to be configured In the Connections pane, expand the server, then expand Sites and select the site to be configured In the Actions pane, click Bindings; the Site Bindings dialog appears If an HTTPS binding is available, click Close and see below 'To require SSL' If no HTTPS binding is visible, perform the following steps To add an HTTPS binding: In the Site Bindings dialog, click Add; the Add Site Binding dialog appears Under Type, select https Under SSL certificate, select an SSL certificate Click OK, then close To require SSL: In Features View, double-click SSL Settings On the SSL Settings page, select Require SSL, and Require 128-bit SSL In the Actions pane, click Apply

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf