IIS 6.0 mitigating BEAST

Posted by D3l_Gato on Server Fault See other posts from Server Fault or by D3l_Gato
Published on 2012-12-07T16:40:25Z Indexed on 2012/12/07 17:10 UTC
Read the original article Hit count: 235

Filed under:
|
|

Recently, my PCI assessor informed me that my servers are vulnerable to BEAST and failed me. I did my homework and I want to change our webservers to prefer RC4 ciphers over CBC. I followed every guide I could find...

I changed my reg keys for my weaker than 128bit encryption to Enabled = 0. completely removed the reg keys for the weaker encryptions. I downloaded IISCrypto and unchecked everything but RC4 128 ciphers and triple DES 168.

My webserver still prefers AES-256SHA. Is there a trick in IIS 6.0 to get your webservers to prefer RC4 ciphers that I am not figuring out? It seems like in IIS 7 they made this very easy to fix but that doesn't help me now!

© Server Fault or respective owner

Related posts about ssl

Related posts about iis6