Re: SSL Weak Ciphers
Ron Gula <[email protected]> Thu, 26 Feb 2009 21:47:36 -0500
| Newsgroups | gmane.comp.security.nessus.general |
|---|---|
| Message-ID | <[email protected]> |
Mark Timm wrote: > On Windows Server 2003 how do I remediate Nessus IDs 26928 and 31705. I= =B9ve > already changed these entries at > SYSTEM\CurrentControlSet\Control\SecurityProvidersSCHANNEL\Ciphers to > Enabled =3D 0: > = > DES 56/56 > NULL > RC2 40/128 > RC4 40/128 > RC4 56/128 > = > I=B9ve also changed these entries at SCHANNEL\Protocols to Enabled =3D 0: > = > PCT 1.0\Client > PCT 1.0\Server > SSL 2.0\Client > SSL 2.0\Server > = > And the vulnerabilities are still reported. I personally have not had to do this on an W2003 system. I did see this KB at Microsoft: http://support.microsoft.com/kb/245030 There was also a blog that summed it up. http://blog.techstacks.com/2008/10/iis-disabling-sslv2-and-weak-ciphers.htm= l#links (Please move questions like this to the new discussions forum.) Ron Gula Tenable Network Security _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus