1.7.11 Configure Triple DES Cipher Suites

Information

This item is Not Scored for the following reasons: Enabling AES 256/256 is recommended. This cipher does not suffer from known practical attacks.

Solution

to enable triple des 168/168, ensure the following key is set to 0xffffffff. the triple des 168/168 cipher is not enabled by default on server 2008 sp2 and is enabled by default on server 2008 r2. hklm\system\currentcontrolset\control\securityproviders\schannel\ciphers\triple des 168/168\enabled

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: 7a207fccca79a998e696a15b0029f112f4757594567a5b10d8552f401d9e8cd1