Solved

PCI Compliance - SBS 2008

Posted on 2014-11-07
9
1,705 Views
Last Modified: 2015-02-22
Evening All

A client of mine has recently failed his PCI compliance test on two areas:

1: SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)
Resolution: Disable SSLv3.

2: Microsoft Exchange Client Access Server Information Disclosure
Resolution: There is no known fix at this time.

Originally he failed the test a few months back because of the standard certificate his server was using, we managed to rectify this by installing a verified SSL cert. We also had to disable SSLv2 on the server as the test was also complaining about this.

Now can anybody advise if disabling SSLv3 is ok to do as I'm almost certain we need at least one variant of it running on the server.

As for the exchange error, if there is no known fix how can security metrics expect my client to pass the test?

Any help is greatly appreciated!
0
Comment
Question by:Daniel Bertolone
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 40429543
Use this script to set your security suites

There is a workaround for the information disclosure and it means editing all of the basic authentication and changing the realm to your fqdn and not leaving it blank
http://blog.kurtiskent.com/2014/09/workaround-for-iis-multiple-internal-ip.html
set-perfectFSecutity.ps1.txt
0
 
LVL 35

Assisted Solution

by:Cris Hanna
Cris Hanna earned 250 total points
ID: 40430252
Yes there is a vulnerability in SSL v3, so it does need to be disabled, v2 should be ok.  Is you customer actually storing credit card information on their server?
0
 

Author Comment

by:Daniel Bertolone
ID: 40432414
Hi Cris

I just confirmed with my client and he does not store credit card info on his server, he takes card payments via his website that is hosted externally to his company. In this case should the security metrics test be pointing at the location of where his website is hosted & not at his on premise server.
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 40432481
That would be correct, almost.  I suspect that some third party is actually doing the credit card transactions for the website, so then the question becomes is cc information being stored on the web server, or by the 3rd party?
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:Daniel Bertolone
ID: 40433595
Thanks Cris,

The cc information is being held by a 3rd party (ekm powershop), i have just spoken with security metrics who run the PCI compliance test and they have advised that my clients server must still be be compliant. They advised that ssl 3.0 is disabled and to use TLS 1.0 as a minimum.

Now my question is that in the below registry key i only have a ssl 2.0 folder.
HKey_Local_Machine\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols

To disable ssl3.0 and enable tls 1.0 i have read online that i can create an ssl3.0 folder and enter the necessary dword value?
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 40433626
use the powershell script I provided
0
 

Author Comment

by:Daniel Bertolone
ID: 40433646
Thanks David, i have just run the script and made the IIS adjustments, i will let you know how the test goes!
0
 

Author Comment

by:Daniel Bertolone
ID: 40433956
Test results came back as a pass, thanks for your prompt & accurate assistance, it's aporeciated!

Cris - thanks for your input on the issue!
0
 

Expert Comment

by:Steph_M
ID: 40624235
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

You may have discovered the 'Compatibility View Settings' workaround for making your SBS 2008 Remote Web Workplace 'connect to a computer' section stops 'working around' after a Windows 10 client upgrade.  That can be fixed so it 'works around' agai…
By default, Carbonite Server Backup manages your encryption key for you using Advanced Encryption Standard (AES) 128-bit encryption. If you choose to manage your private encryption key, your backups will be encrypted using AES 256-bit encryption.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now