WA000-WI6180 IIS7 - The production website must utilize SHA1 encryption for Machine Key.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Machine Key element of the ASP.NET web.config specifies the algorithm and keys that
ASP.NET will use for encryption. The Machine Key feature can be managed to specify hashing and encryption settings for application services such as view state, forms authentication, membership and roles, and anonymous identification. Ensuring a strong encryption method can mitigate the risk of data tampering in crucial functional areas such as forms authentication cookies or view state.

Solution

1. Open the 'IIS Manager'.
2. Click the site name under review.
3. Double-click the 'Machine Key' in the website 'Home Pane'.
4. Set the 'Validation method' to 'SHA1'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CAT|II, Rule-ID|SV-33314r4_rule, STIG-ID|WA000-WI6180_IIS7, Vuln-ID|V-26026

Plugin: Windows

Control ID: f11c7df1e593fc76ccb233aafab44adddcfa372f9e1ed9b96464d8e3b5863d09