Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Improve Security on SBS 2011

Posted on 2016-09-12
5
Medium Priority
?
42 Views
Last Modified: 2016-10-08
HI -
We are trying to be more secure so a client can accept credit cards.  The firm that inspects our vulnerabilities produced the following.  I thought i had addressed this in the security section of SBS 2011 but it appears that i did not.  Any, and all, detailed information on how to correct this would be so appreciated.

Thanks
Rich
The SSL-based service running on this host appears to support the use of "weak" ciphers such as:

- Ciphers suites that have key-lengths of less than 128 bits.

- Ciphers suites using anonymous Diffie-Hellman algorithms (no authentication).

- Ciphers suites offering no encryption.

- Ciphers suites using pre-shared keys.

- Ciphers suites using RC4 or MD5.
0
Comment
Question by:webentpr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 65

Accepted Solution

by:
btan earned 1000 total points (awarded by participants)
ID: 41794434
Try running iiscrypto using its best practice. It helps to set the cipher required in baseline to secure the server to use strong cipher. This only set the cipher on the OS and you need to make sure the appl config changes separately, applicable.
https://www.nartac.com/Support/IISCrypto/FAQ

https://www.nartac.com/Blog/post/2013/04/19/IIS-Crypto-Explained.aspx

If server is accessible via Internet, I suggest a self assessment using the ssl lab test. It does a good snapshot on the cipher used.
https://www.ssllabs.com/ssltest/
0
 
LVL 30

Assisted Solution

by:pgm554
pgm554 earned 1000 total points (awarded by participants)
ID: 41794656
0
 

Author Comment

by:webentpr
ID: 41796398
First let me apologize for taking so long to respond.  I will try this - thank you.
0
 

Author Comment

by:webentpr
ID: 41804881
Thanks - everything worked correctly - really appreciate your help.
Rich
0
 
LVL 65

Expert Comment

by:btan
ID: 41834886
As per advised and acknowledged.
0

Featured Post

Protect Your Retail Business and Reputation

Wi-Fi access doesn't just impact your business & customer experience, it can also affect your security.  Join us for an informative webinar to learn more about the top threats and trends impacting retail today, and the key solutions to protecting retail networks and reputations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question