1.7.5 Configure TLS 1.1 - 'DisabledByDefault = 0'

Information

This item is Not Scored for the following reasons: Enabling TLS 1.2 is recommended. This protocol does not suffer from known practical attacks.

Solution

perform the following to enable tls 1.1: 1. set the following key to 0xffffffff hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.1\server\enabled 2. set the following key to 0 hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.1\server\disabledbydefault

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: fab5ef0b91bd698227aba3c993ea2ac720561a798694b0629ef447b6edff4396