HTTP over SSL removed?

1etherer

Fully Optimized
Messages
1,878
Location
Earth
Hi all,

We patched our web server and since then SSL has been removed from HTTP and I want to know how to enable it again, im guessing its done in IIS? but I dont know much about it and I cant find a guide on it...

So please reply in dummy talk :cool::cool:
 
have you also removed SSLv3/TLS1.0/1.1 and using only TLS1.2 on the web server?

This is a old thread, I'm not longer at that company. But no I never touched the rest, I just put the cert back on.

If you feel this is another step people should know, please provide the steps or a link would be useful. :cool:
 
This is a old thread, I'm not longer at that company. But no I never touched the rest, I just put the cert back on.

If you feel this is another step people should know, please provide the steps or a link would be useful. :cool:

bleh, sorry, didn't realize the original post date. I was doing 15 things at the time haha.

ya, no doubt more steps. not sure why Microsoft just doesn't push out an update to force TLS 1.2 as default on IIS. even if the application doesn't support 1.2 it will negotiate down the list and use the best possible. anything below TLS 1.2 shouldn't be used right now. TLS 1.0 is the default in IIS and it can potentially be downgraded to SSLv3, which, can be broken.

i'll post the registry edits tomorrow when i'm at work with suggestions and steps. probably in it's own thread though. lots to talk about that I don't see on here.
 
Back
Top Bottom