Solved

Disabling RC4 Cipher On Windows Server 2008 Service Pack 2

Posted on 2014-11-04
2
1,724 Views
Last Modified: 2014-11-05
Hello Experts,
Vulnerability with regards to our OWA web site using RC4 cipher algorithms in SSL cipher suites has been identified.  I have been reading on how to remediate this issue and I’m thinking that disabling RC4 is the way to go.  Our Exchange server is running Windows Server 2008 with service pack 2.  We are running Exchange 2007.  I have been reading on how to disable the RC4 cipher algorithms and everything I have read states I need to modify the following registry keys:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]
"Enabled"=dword:00000000
The problem I’m running into is these registry keys do not exist.  Should I create the following subkeys and dword values within each sub-key?
Sub-keys:
RC4 128/128
RC4 40/128
RC4 56/128.

Dword Values:
“Enabled”=dword:00000000

Any clarification will be greatly appreciated.

Nick
0
Comment
Question by:ndalmolin_13
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 12

Accepted Solution

by:
David Paris Vicente earned 500 total points
ID: 40422879
Hi ndalmolin_13,

This case is similar to one that I answered in the past for other protocols but it was to 2003, you can check it here

In your case if you don´t have that Keys you should create them and run the security test again to check if anything else is reported regarding the RC4 in SSL,
of course before doing any change to the registry you should backup

I hope it helps.

Regards
0
 
LVL 1

Author Closing Comment

by:ndalmolin_13
ID: 40424401
Thanks for the info
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question