<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows / IIS SSL &#8211; Restrict Weak Ciphers</title>
	<atom:link href="http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/</link>
	<description>Another TechBlog</description>
	<lastBuildDate>Tue, 25 May 2010 18:20:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Removing weak ciphers / protocols from Windows Server 2003 IIS 6 &#171; Jonathan McLeod Blog</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-482</link>
		<dc:creator>Removing weak ciphers / protocols from Windows Server 2003 IIS 6 &#171; Jonathan McLeod Blog</dc:creator>
		<pubDate>Tue, 25 May 2010 18:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-482</guid>
		<description>[...] http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/" rel="nofollow">http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-193</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Thu, 21 May 2009 19:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-193</guid>
		<description>Hello
In reply to John

It does scan any and all servers behind the public ip...  Assuming that this is a netscaler / load balancer for multiple web servers.  The Virtual IP assigned represents all of the backend physical ips associated to the individual web sites.  Best bet is to determine the physical ips associated to the Virtual IP that is throwing a positive from the scan.  When that is done you&#039;ll need to find the actual servers that these reside on.  Apply these patches as directed above to those servers.  Make sure you capture / back up the existing entries in the registry as I have seen this cause client issues with non IE browsers.

Good Luck!

Steve</description>
		<content:encoded><![CDATA[<p>Hello<br />
In reply to John</p>
<p>It does scan any and all servers behind the public ip&#8230;  Assuming that this is a netscaler / load balancer for multiple web servers.  The Virtual IP assigned represents all of the backend physical ips associated to the individual web sites.  Best bet is to determine the physical ips associated to the Virtual IP that is throwing a positive from the scan.  When that is done you&#8217;ll need to find the actual servers that these reside on.  Apply these patches as directed above to those servers.  Make sure you capture / back up the existing entries in the registry as I have seen this cause client issues with non IE browsers.</p>
<p>Good Luck!</p>
<p>Steve</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-192</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 27 Apr 2009 23:56:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-192</guid>
		<description>Hello,

I am having the same problems with these ciphers and security metrics.  I have disabled everything lower than 128 and I am still not passing the scan.  Does anyone know if security metrics scans every server and workstation behind our Public IP or is it just the server that is port forwarded?  I have been working on this for almost a month now and the security metrics tech support is of no help at ALL (what a joke), they do not even know what their tests scans!!  Any help would be greatly appreciated.

Thanks!</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I am having the same problems with these ciphers and security metrics.  I have disabled everything lower than 128 and I am still not passing the scan.  Does anyone know if security metrics scans every server and workstation behind our Public IP or is it just the server that is port forwarded?  I have been working on this for almost a month now and the security metrics tech support is of no help at ALL (what a joke), they do not even know what their tests scans!!  Any help would be greatly appreciated.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clamasters</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-190</link>
		<dc:creator>clamasters</dc:creator>
		<pubDate>Mon, 30 Mar 2009 17:00:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-190</guid>
		<description>Your mileage may vary.  I have run this on 30 plus servers with zero issues but usually depending on the OS/Browser version of the client viewing the site/application, you may experience issues.</description>
		<content:encoded><![CDATA[<p>Your mileage may vary.  I have run this on 30 plus servers with zero issues but usually depending on the OS/Browser version of the client viewing the site/application, you may experience issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yong</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-189</link>
		<dc:creator>Yong</dc:creator>
		<pubDate>Mon, 30 Mar 2009 16:16:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-189</guid>
		<description>Any of this alteration affect your application?</description>
		<content:encoded><![CDATA[<p>Any of this alteration affect your application?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marty</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-184</link>
		<dc:creator>Marty</dc:creator>
		<pubDate>Fri, 27 Feb 2009 01:35:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-184</guid>
		<description>Mahalo Nui Loa (Thank you very much in Hawaiian)

Your solution worked great!!!  Really appreciate you publishing it.</description>
		<content:encoded><![CDATA[<p>Mahalo Nui Loa (Thank you very much in Hawaiian)</p>
<p>Your solution worked great!!!  Really appreciate you publishing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Calazan</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-180</link>
		<dc:creator>Calazan</dc:creator>
		<pubDate>Wed, 28 Jan 2009 00:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-180</guid>
		<description>Thanks! We passed the SecurityMetrics PCI scan by following your instructions.

Pav, for us we disabled the following:
DES 56/56
RC2 40/128
RC4 40/128
RC4 56/128.

And like the others said, SSL 2.0 support should also be disabled.</description>
		<content:encoded><![CDATA[<p>Thanks! We passed the SecurityMetrics PCI scan by following your instructions.</p>
<p>Pav, for us we disabled the following:<br />
DES 56/56<br />
RC2 40/128<br />
RC4 40/128<br />
RC4 56/128.</p>
<p>And like the others said, SSL 2.0 support should also be disabled.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; IIS Security Scan: The remote service supports the use of weak SSL ciphers Calazan.com: Share the Knowledge</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-179</link>
		<dc:creator>&#187; IIS Security Scan: The remote service supports the use of weak SSL ciphers Calazan.com: Share the Knowledge</dc:creator>
		<pubDate>Wed, 28 Jan 2009 00:42:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-179</guid>
		<description>[...] goes to this website for this solution: http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/  addthis_url = [...]</description>
		<content:encoded><![CDATA[<p>[...] goes to this website for this solution: <a href="http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/" rel="nofollow">http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/</a>  addthis_url = [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-177</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Thu, 22 Jan 2009 22:29:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-177</guid>
		<description>Everyone&#039;s one a PCI compliance kick...this: http://support.microsoft.com/kb/245030/en-us 
tells how to only support SSL 3.0 or TLS 1.0 and not SSL 2.0

in a nutshell:
regedit to HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols 
then set the below to dword &quot;Enabled&quot;, value 0x0

\PCT 1.0\Client
\PCT 1.0\Server
\SSL 2.0\Client
\SSL 2.0\Server</description>
		<content:encoded><![CDATA[<p>Everyone&#8217;s one a PCI compliance kick&#8230;this: <a href="http://support.microsoft.com/kb/245030/en-us" rel="nofollow">http://support.microsoft.com/kb/245030/en-us</a><br />
tells how to only support SSL 3.0 or TLS 1.0 and not SSL 2.0</p>
<p>in a nutshell:<br />
regedit to HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols<br />
then set the below to dword &#8220;Enabled&#8221;, value 0&#215;0</p>
<p>\PCT 1.0\Client<br />
\PCT 1.0\Server<br />
\SSL 2.0\Client<br />
\SSL 2.0\Server</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pav</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-176</link>
		<dc:creator>Pav</dc:creator>
		<pubDate>Tue, 20 Jan 2009 14:37:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-176</guid>
		<description>James, Joey - did it sort out Security Metrics for you. I&#039;m still having problems with the ciphers. Let me know if you got it right.</description>
		<content:encoded><![CDATA[<p>James, Joey &#8211; did it sort out Security Metrics for you. I&#8217;m still having problems with the ciphers. Let me know if you got it right.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
