Skip to main content

Disable SSLV2 & Weak SSL Ciphers on IIS

Seems that there is a lot of confusion for people who manage windows/IIS servers and need to disable SSL 2 and older weaker encryption. There are are few nice articles, but can sometimes be confusing unless you really know your way around the Windows Registry. I hope I can simplify this for some people.


Important: There is no need to purchase a utility to do this. Save the money. Some companies charge you $20 or more per server to have a utility to easily click and enable/disable these services.Ok here is the help. For techies who want reference material, here is the good stuff:
The easy part: I have created a .reg file you can download and merge on your windows 2003 server that will disable ssl2 and weak ciphers. Important: This works for me, your mileage may vary. Always backup first. I won't help you if you break your server because you didn't do a backup first. You can test your server to see if you have SSL2 still enabled by going to here: http://foundeo.com/products/iis-weak-ssl-ciphers/test.cfm Download: disable_weak_ciphers.reg (downloads as a text file, then rename it to have a .reg extension)

Download this file, rename it to have a .reg extension, right click on it and merge it into the registry. Then do a reboot and when the server comes back online, test again with the above link -- SSL2 should be disabled.

Tweak as you like, no warranty! no warranty! By using this you indemnify me from any liabilities!!!

If this helped you and saved you money, then let me know :) If you feel really compelled to spend money, then donate a few $'s to me by paypal at aschwabe (at) gmail (dot) com.

Cheers

Popular posts from this blog

Installing python 3.4.x on OSX El Capitan

I love "brew" package manager, but sometimes being too progressive breaks things.  I have several python apps that I maintain that get deployed to AWS using Elastic Beanstalk.  AWS eb can deploy with python 2.7 or 3.4.  Any recent 'brew install python3" will get 3.5.1. #annoying

Making Macbook Air with 128GB SSD usable with Bootcamp

I recently got a new Macbook Air 11" (the 2012 version) and loaded it with goodies like 8GB ram and 2GHz Core i7.  What I DIDN'T upgrade was the internal SSD.  My config came with 128GB SSD and I refused to pay $300+ to upgrade it to 256GB.  Yeah I know, some call me cheap, but SSds cost $75-$150 for 240GB, so adding another 128GB for $300 seemed way too steep for me.  I figured "ok, I'm going to make 128G work!"

Here is the story of how that went...

Getting Started with OpenVAS on CentOS - an open source vulnerability scanner

The Open Vulnerability Assessment System (OpenVAS) is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution. (Taken from the OpenVAS website, which is at http://www.openvas.org/ )





This blog entry will introduce OpenVAS version 3.1, walk through installation on CentOS and is intended as a "getting started" guide. I'll also do a guide for installing on Ubuntu later.