IIS 6.0 mitigating BEAST
Posted
by
D3l_Gato
on Server Fault
See other posts from Server Fault
or by D3l_Gato
Published on 2012-12-07T16:40:25Z
Indexed on
2012/12/07
17:10 UTC
Read the original article
Hit count: 235
Recently, my PCI assessor informed me that my servers are vulnerable to BEAST and failed me. I did my homework and I want to change our webservers to prefer RC4 ciphers over CBC. I followed every guide I could find...
I changed my reg keys for my weaker than 128bit encryption to Enabled = 0. completely removed the reg keys for the weaker encryptions. I downloaded IISCrypto and unchecked everything but RC4 128 ciphers and triple DES 168.
My webserver still prefers AES-256SHA. Is there a trick in IIS 6.0 to get your webservers to prefer RC4 ciphers that I am not figuring out? It seems like in IIS 7 they made this very easy to fix but that doesn't help me now!
© Server Fault or respective owner