<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows / IIS SSL &#8211; Restrict Weak Ciphers</title>
	<atom:link href="http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/</link>
	<description>Another TechBlog</description>
	<lastBuildDate>Mon, 16 Jan 2012 19:30:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jeff</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-639</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Wed, 11 May 2011 22:58:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-639</guid>
		<description>I just published a free tool that can disable weak protocols and ciphers.  Essentially it uses the same registry keys as those articles listed but adds a simple GUI to configure Windows Server 2003/2008.

It is called IIS Crypto and found here: https://www.nartac.com/Products/IISCrypto/Default.aspx</description>
		<content:encoded><![CDATA[<p>I just published a free tool that can disable weak protocols and ciphers.  Essentially it uses the same registry keys as those articles listed but adds a simple GUI to configure Windows Server 2003/2008.</p>
<p>It is called IIS Crypto and found here: <a href="https://www.nartac.com/Products/IISCrypto/Default.aspx" rel="nofollow">https://www.nartac.com/Products/IISCrypto/Default.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clamasters</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-604</link>
		<dc:creator>clamasters</dc:creator>
		<pubDate>Sun, 20 Feb 2011 15:20:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-604</guid>
		<description>I tried to do some reserch on this as I have not personally had to do it myself.  Microsoft&#039;s documenation is scary thin for 2008 in regards to cipher security.  Everything that I have read points to the same KB article. &lt;a href=&quot;http://support.microsoft.com/default.aspx?scid=kb;EN-US;245030&quot; rel=&quot;nofollow&quot;&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;245030&lt;/a&gt;

I did find this tidbit though.  &lt;a href=&quot;http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cf01f33-9cbe-4b76-b01c-83923c4cda04&quot; rel=&quot;nofollow&quot;&gt;http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cf01f33-9cbe-4b76-b01c-83923c4cda04&lt;/a&gt;

Hopefully this helps.</description>
		<content:encoded><![CDATA[<p>I tried to do some reserch on this as I have not personally had to do it myself.  Microsoft&#8217;s documenation is scary thin for 2008 in regards to cipher security.  Everything that I have read points to the same KB article. <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;245030" rel="nofollow">http://support.microsoft.com/default.aspx?scid=kb;EN-US;245030</a></p>
<p>I did find this tidbit though.  <a href="http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cf01f33-9cbe-4b76-b01c-83923c4cda04" rel="nofollow">http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cf01f33-9cbe-4b76-b01c-83923c4cda04</a></p>
<p>Hopefully this helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-601</link>
		<dc:creator>Sebastian</dc:creator>
		<pubDate>Wed, 16 Feb 2011 22:21:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-601</guid>
		<description>Any Idea on how to do it in Windows 2008 as thesubkeys for cipher does not exist.
Do I need to create the subkeys manually?? If I need to do that, I need to create the complete set as they exists in Windows 2003?
Thanks</description>
		<content:encoded><![CDATA[<p>Any Idea on how to do it in Windows 2008 as thesubkeys for cipher does not exist.<br />
Do I need to create the subkeys manually?? If I need to do that, I need to create the complete set as they exists in Windows 2003?<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eman</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-558</link>
		<dc:creator>Eman</dc:creator>
		<pubDate>Sat, 30 Oct 2010 00:31:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-558</guid>
		<description>Thanks, this helped me resolve the PCI security issue I was getting with http://www.trustmonitor.com vulnerability scanning.</description>
		<content:encoded><![CDATA[<p>Thanks, this helped me resolve the PCI security issue I was getting with <a href="http://www.trustmonitor.com" rel="nofollow">http://www.trustmonitor.com</a> vulnerability scanning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chanda</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-508</link>
		<dc:creator>chanda</dc:creator>
		<pubDate>Tue, 27 Jul 2010 02:29:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-508</guid>
		<description>fairly new...at SSL, I know this thread is VERY OLD, but can some one tell me how to do this:

Pav, for us we disabled the following:
DES 56/56
RC2 40/128
RC4 40/128
RC4 56/128.

I dont have a clue..as I said, i&#039;m new at this..</description>
		<content:encoded><![CDATA[<p>fairly new&#8230;at SSL, I know this thread is VERY OLD, but can some one tell me how to do this:</p>
<p>Pav, for us we disabled the following:<br />
DES 56/56<br />
RC2 40/128<br />
RC4 40/128<br />
RC4 56/128.</p>
<p>I dont have a clue..as I said, i&#8217;m new at this..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Removing weak ciphers / protocols from Windows Server 2003 IIS 6 &#171; Jonathan McLeod Blog</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-482</link>
		<dc:creator>Removing weak ciphers / protocols from Windows Server 2003 IIS 6 &#171; Jonathan McLeod Blog</dc:creator>
		<pubDate>Tue, 25 May 2010 18:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-482</guid>
		<description>[...] http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/" rel="nofollow">http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-193</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Thu, 21 May 2009 19:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-193</guid>
		<description>Hello
In reply to John

It does scan any and all servers behind the public ip...  Assuming that this is a netscaler / load balancer for multiple web servers.  The Virtual IP assigned represents all of the backend physical ips associated to the individual web sites.  Best bet is to determine the physical ips associated to the Virtual IP that is throwing a positive from the scan.  When that is done you&#039;ll need to find the actual servers that these reside on.  Apply these patches as directed above to those servers.  Make sure you capture / back up the existing entries in the registry as I have seen this cause client issues with non IE browsers.

Good Luck!

Steve</description>
		<content:encoded><![CDATA[<p>Hello<br />
In reply to John</p>
<p>It does scan any and all servers behind the public ip&#8230;  Assuming that this is a netscaler / load balancer for multiple web servers.  The Virtual IP assigned represents all of the backend physical ips associated to the individual web sites.  Best bet is to determine the physical ips associated to the Virtual IP that is throwing a positive from the scan.  When that is done you&#8217;ll need to find the actual servers that these reside on.  Apply these patches as directed above to those servers.  Make sure you capture / back up the existing entries in the registry as I have seen this cause client issues with non IE browsers.</p>
<p>Good Luck!</p>
<p>Steve</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-192</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 27 Apr 2009 23:56:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-192</guid>
		<description>Hello,

I am having the same problems with these ciphers and security metrics.  I have disabled everything lower than 128 and I am still not passing the scan.  Does anyone know if security metrics scans every server and workstation behind our Public IP or is it just the server that is port forwarded?  I have been working on this for almost a month now and the security metrics tech support is of no help at ALL (what a joke), they do not even know what their tests scans!!  Any help would be greatly appreciated.

Thanks!</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I am having the same problems with these ciphers and security metrics.  I have disabled everything lower than 128 and I am still not passing the scan.  Does anyone know if security metrics scans every server and workstation behind our Public IP or is it just the server that is port forwarded?  I have been working on this for almost a month now and the security metrics tech support is of no help at ALL (what a joke), they do not even know what their tests scans!!  Any help would be greatly appreciated.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clamasters</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-190</link>
		<dc:creator>clamasters</dc:creator>
		<pubDate>Mon, 30 Mar 2009 17:00:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-190</guid>
		<description>Your mileage may vary.  I have run this on 30 plus servers with zero issues but usually depending on the OS/Browser version of the client viewing the site/application, you may experience issues.</description>
		<content:encoded><![CDATA[<p>Your mileage may vary.  I have run this on 30 plus servers with zero issues but usually depending on the OS/Browser version of the client viewing the site/application, you may experience issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yong</title>
		<link>http://www.curtis-lamasters.com/2008/06/21/windows-iis-ssl-restrict-weak-ciphers/comment-page-1/#comment-189</link>
		<dc:creator>Yong</dc:creator>
		<pubDate>Mon, 30 Mar 2009 16:16:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.curtis-lamasters.com/?p=86#comment-189</guid>
		<description>Any of this alteration affect your application?</description>
		<content:encoded><![CDATA[<p>Any of this alteration affect your application?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

