1.7.3 Disable SSLv3 - 'DisabledByDefault = 1'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disabling weak protocols will help ensure the confidentiality and integrity of in-transit data.

Solution

perform the following to disable ssl 3.0: 1. set the following key to 1. hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\ssl 3.0\server\disabledbydefault 2. set the following keyto 0. hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\ssl 3.0\server\enabled

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: bf3c38c16fde9c4cb0adde7c4ec41a58cca8f325b4f4840c53094526db16b825