1.7.4 Configure TLS 1.0 - 'Enabled = 0xFFFFFFFF'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enabling this protocol will help ensure the confidentiality and integrity of data in transit. This recommendation is Not Scored for the IIS 7.5 profile as Windows Server 2008 R2 and IIS 7.5 support TLS 1.2, which is recommended protocol for that platform.

Solution

perform the following to enable tls 1.0: 1. set the following key to 0xffffffff hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.0\server\enabled 2. set the following key to 0 hklm\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.0\server\disabledbydefault

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: 5a6250f1bc29acaf5564221572fc092b9d7e4b2bd383220f9126d2735b1b8e03