Re: SSL Weak Ciphers

Ron Gula <[email protected]> Thu, 26 Feb 2009 21:47:36 -0500
Newsgroups gmane.comp.security.nessus.general
Message-ID <[email protected]>
Mark Timm wrote:
> On Windows Server 2003 how do I remediate Nessus IDs 26928 and 31705.  I=
=B9ve
> already changed these entries at
> SYSTEM\CurrentControlSet\Control\SecurityProvidersSCHANNEL\Ciphers to
> Enabled =3D 0:
> =

> DES 56/56
> NULL
> RC2 40/128
> RC4 40/128
> RC4 56/128
> =

> I=B9ve also changed these entries at SCHANNEL\Protocols to Enabled =3D 0:
> =

> PCT 1.0\Client
> PCT 1.0\Server
> SSL 2.0\Client
> SSL 2.0\Server
> =

> And the vulnerabilities are still reported.

I personally have not had to do this on an W2003 system. I did see this
KB at Microsoft:

http://support.microsoft.com/kb/245030

There was also a blog that summed it up.

http://blog.techstacks.com/2008/10/iis-disabling-sslv2-and-weak-ciphers.htm=
l#links

(Please move questions like this to the new discussions forum.)

Ron Gula
Tenable Network Security

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus