Solved

Disabling RC4 Cipher On Windows Server 2008 Service Pack 2

Posted on 2014-11-04
2
1,639 Views
Last Modified: 2014-11-05
Hello Experts,
Vulnerability with regards to our OWA web site using RC4 cipher algorithms in SSL cipher suites has been identified.  I have been reading on how to remediate this issue and I’m thinking that disabling RC4 is the way to go.  Our Exchange server is running Windows Server 2008 with service pack 2.  We are running Exchange 2007.  I have been reading on how to disable the RC4 cipher algorithms and everything I have read states I need to modify the following registry keys:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]
"Enabled"=dword:00000000
The problem I’m running into is these registry keys do not exist.  Should I create the following subkeys and dword values within each sub-key?
Sub-keys:
RC4 128/128
RC4 40/128
RC4 56/128.

Dword Values:
“Enabled”=dword:00000000

Any clarification will be greatly appreciated.

Nick
0
Comment
Question by:ndalmolin_13
2 Comments
 
LVL 12

Accepted Solution

by:
David Paris Vicente earned 500 total points
ID: 40422879
Hi ndalmolin_13,

This case is similar to one that I answered in the past for other protocols but it was to 2003, you can check it here

In your case if you don´t have that Keys you should create them and run the security test again to check if anything else is reported regarding the RC4 in SSL,
of course before doing any change to the registry you should backup

I hope it helps.

Regards
0
 
LVL 1

Author Closing Comment

by:ndalmolin_13
ID: 40424401
Thanks for the info
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
how to add IIS SMTP to handle application/Scanner relays into office 365.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question