Solved

How to I enable SSL 3 for ADFS running on a Windows Server 2012 R2?

Posted on 2014-10-03
2
1,612 Views
Last Modified: 2014-10-04
We recently setup ADFS as part of our implementation of Office 365.  In setting up ADFS to authenticate to a second service we subscribe to, we were told by the vendor that our ADFS servers need to support SSL 3.  

Being new to ADFS, I took to the web put I am unable to find any documentation on how to do this.  I have tried the registry edit to enable SSL 3.0 for IIS that I found, but the ssl test site the vendor is using is still showing that it isn't enabled.

Any suggestions?
0
Comment
Question by:bumb_1
2 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 500 total points
ID: 40360452
Take a look at disabling V2 then you should be able to pass their test for V3

SSL v2 is weak and outdated protocol. All modern browsers support SSL v3 and it's enabled by default on Windows 2008 (IIS 7 / IIS 7.5). To make sure all clients are using SSL v3 we must disable SSL v2. This is required for PCI compliance.

This is what needs to be done to disable SSL v2:

1. Start - Run
2. Type "regedit" and click OK
3. Locate the following key: HKey_Local_Machine\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0
4. Right click the "SSL 2.0" key and select Edit > Add key
5. Type "Server" and click Enter
6. Right click Server and select New > Add DWORD (32 bit) value
7. Type "Enabled" as the name and make sure the value is "0"
8. Restart the server


Reprinted from:
http://www.aip.im/2012/03/how-to-disable-ssl-v2-enable-ssl-v3-on-windows-2008/
0
 

Author Closing Comment

by:bumb_1
ID: 40361487
That did the trick
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question