Solved

Disabling RC4 Cipher On Windows Server 2008 Service Pack 2

Posted on 2014-11-04
2
1,564 Views
Last Modified: 2014-11-05
Hello Experts,
Vulnerability with regards to our OWA web site using RC4 cipher algorithms in SSL cipher suites has been identified.  I have been reading on how to remediate this issue and I’m thinking that disabling RC4 is the way to go.  Our Exchange server is running Windows Server 2008 with service pack 2.  We are running Exchange 2007.  I have been reading on how to disable the RC4 cipher algorithms and everything I have read states I need to modify the following registry keys:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]
"Enabled"=dword:00000000
The problem I’m running into is these registry keys do not exist.  Should I create the following subkeys and dword values within each sub-key?
Sub-keys:
RC4 128/128
RC4 40/128
RC4 56/128.

Dword Values:
“Enabled”=dword:00000000

Any clarification will be greatly appreciated.

Nick
0
Comment
Question by:ndalmolin_13
2 Comments
 
LVL 12

Accepted Solution

by:
David Paris Vicente earned 500 total points
ID: 40422879
Hi ndalmolin_13,

This case is similar to one that I answered in the past for other protocols but it was to 2003, you can check it here

In your case if you don´t have that Keys you should create them and run the security test again to check if anything else is reported regarding the RC4 in SSL,
of course before doing any change to the registry you should backup

I hope it helps.

Regards
0
 
LVL 1

Author Closing Comment

by:ndalmolin_13
ID: 40424401
Thanks for the info
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Read this checklist to learn more about the 15 things you should never include in an email signature.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
how to add IIS SMTP to handle application/Scanner relays into office 365.

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question