WG340 - A Private web server is not using TLS - 'HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Client'

Information

Vulnerability Key: V0002262
IA Controls: ECCT-1 Encryption for Confidentiality (Data in Transit), ECCT-2 Encryption for Confidentiality (Data in Transit)
Categories: 1.2 PKI
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.13, 8520.2 Public Key Infrastructure (PKI)
and Public Key (PK) Enabling
SSL/TLS encryption is a required security setting for a private web server. This check precludes the
possibility that a valid certificate has been obtained, but SSL/TLS has not been activated or is not
being used. Transactions encrypted with trusted certificates are necessary when the information being
transferred is not intended to be accessed by all parties on the network. To the extent that this
standard applies, this check is valid for the SIPRNet also. In addition, the use of current technologies
will lessen the risk of data exposure due to limitations in the encryption that is being utilized. The
minimum standard is SSL V3.1 / TLS 1.0.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: d274be92dcacd0946762e5df44af45f3b8020bfa76a2a0cb378f36f7cec1b135