DTBI1100-IE11 - Allow Fallback to SSL 3.0 (Internet Explorer) must be disabled.

Information

This parameter ensures only DoD-approved ciphers and algorithms are enabled for use by the web browser by blocking an insecure fallback to SSL when TLS 1.0 or greater fails.

Solution

Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Security Features >> 'Allow fallback to SSL 3.0 (Internet Explorer)' to 'Enabled', and select 'No Sites' from the drop-down box.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IE11_V1R18_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-002450, Rule-ID|SV-79219r3_rule, STIG-ID|DTBI1100-IE11, Vuln-ID|V-64729

Plugin: Windows

Control ID: 0b314b5798f6fad5db25fc79e33321be86a091d3101f4cdc7c0cdcfca59b8a5c