Disabling weak cipher suites in IIS (2024)

Table of Contents
Before you begin Procedure

By default, IIS is installed with 2 weak SSL 2.0 ciphersuites that are enabled: SSL2_RC4_128_WITH_MD5 andSSL2_DES_192_EDE3_CBC_WITH_MD5. This can impact the securityof AppScan Enterprise, and the cipher suites should be disabled.

Before you begin

Incorrectly editing the registry may severely damageyoursystem. Before making changes to the registry, you should back upany valued data on your computer.

Procedure

  1. Open theRegistry Editor (Start > Run > regedit).
  2. Inthe HKEY_LOCAL_MAC HINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers directory:
    1. Create a new key called RC4 128/128 (Ciphers > New > KeyRC4 128/128).
    2. Right-click the key's name and create a new DWORD (32-bit)Value called 'Enabled'. (New > DWORD (32-bit) Value > Enabled).
    3. Leave the default valueas '0'.
  3. In the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes directory:
    1. Create a key called MD5 (Hashes > New > Key > MD5).
    2. Right-clickthe key's name and create a new DWORD (32-bit)Value called 'Enabled'. (New > DWORD (32-bit) Value > Enabled).
    3. Leave the default valueas '0'.
  4. Close the RegistryEditor.
Disabling weak cipher suites in IIS (2024)
Top Articles
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 5530

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.