{"id":4922,"date":"2023-11-15T15:45:12","date_gmt":"2023-11-15T23:45:12","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=4922"},"modified":"2023-11-15T15:45:14","modified_gmt":"2023-11-15T23:45:14","slug":"how-to-disable-ssl-v3-on-windows-servers","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=4922","title":{"rendered":"How to Disable SSL V3 on Windows Servers"},"content":{"rendered":"\n<p>The best way is to have this done by a free tool called &#8220;IIS Crypto&#8221; from the Nartac Software. You can download the tool from here.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.nartac.com\/\">https:\/\/www.nartac.com\/<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Below, is a way to get this done manually. but it&#8217;s not recommended.<\/p>\n\n\n\n<p>SSLv3 is an obsolete protocol, the main attack vector on which, at the time of writing, is an attack called\u00a0<a href=\"http:\/\/en.wikipedia.org\/wiki\/POODLE\" target=\"_blank\" rel=\"noreferrer noopener\">POODLE<\/a>. Disabling SSLv3 is the ultimate solution to mitigate security risks. Another option suitable for servers that critically require SSLv3 support is a signalizing TLS_FALLBACK_SCSV cipher suite that allows to keep SSLv3 enabled, but prevents downgrade attacks from higher protocols (TLSv1 =&lt; ). Unfortunately, at the time of writing, Microsoft didn\u2019t yet add support for TLS_FALLBACK_SCSV in SChanel. Therefore, disabling SSLv3 is the only mitigation measure a certificate administrator can apply against POODLE in case of a\u00a0<strong>Windows Server<\/strong>.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Open registry editor:<strong>Win + R<\/strong>\u00a0>>\u00a0<strong><em>regedit<\/em><\/strong><\/li><li>Navigate to:<strong>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\Schannel\\Protocols\\<\/strong><img fetchpriority=\"high\" decoding=\"async\" width=\"885\" height=\"500\" src=\"https:\/\/namecheap.simplekb.com\/SiteContents\/2-7C22D5236A4543EB827F3BD8936E153E\/media\/Hardening_9.jpg\" alt=\"Hardening_9.jpg\"><\/li><li>By default, there should be only one key presented\u00a0<strong>\u201cSSL 2.0\u201d<\/strong>. We need to create a new one for SSLv3Right-click on\u00a0<strong>Protocols<\/strong>\u00a0>>\u00a0<strong>New\u00a0<\/strong>>>\u00a0<strong>Key<\/strong>Name the key\u00a0<em><strong>&#8216;SSL 3.0&#8217;<\/strong><\/em><img decoding=\"async\" width=\"885\" height=\"500\" src=\"https:\/\/namecheap.simplekb.com\/SiteContents\/2-7C22D5236A4543EB827F3BD8936E153E\/media\/Hardening_10.jpg\" alt=\"Hardening_10.jpg\"><\/li><li>Right-click on\u00a0<strong>SSL 3.0<\/strong>\u00a0>>\u00a0<strong>New\u00a0<\/strong>>>\u00a0<strong>Key<\/strong><img decoding=\"async\" width=\"885\" height=\"500\" src=\"https:\/\/namecheap.simplekb.com\/SiteContents\/2-7C22D5236A4543EB827F3BD8936E153E\/media\/Hardening_11.jpg\" alt=\"Hardening_11.jpg\">Name the key\u00a0<em><strong>&#8216;Server&#8217;<\/strong><\/em><\/li><li>Right-click on\u00a0<strong>Server<\/strong>\u00a0>>\u00a0<strong>New\u00a0<\/strong>>>\u00a0<strong>DWORD (32-bit) Value<\/strong><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"500\" src=\"https:\/\/namecheap.simplekb.com\/SiteContents\/2-7C22D5236A4543EB827F3BD8936E153E\/media\/Hardening_12.jpg\" alt=\"Hardening_12.jpg\">Name the value\u00a0<strong>&#8216;<em>Enabled<\/em>&#8216;<\/strong><\/li><li>Double-click the\u00a0<strong>Enabled<\/strong>\u00a0value and make sure that there is zero (0) in the\u00a0<strong>Value Data<\/strong>\u00a0field >> click\u00a0<strong>OK<\/strong><img loading=\"lazy\" decoding=\"async\" width=\"785\" height=\"500\" src=\"https:\/\/namecheap.simplekb.com\/SiteContents\/2-7C22D5236A4543EB827F3BD8936E153E\/media\/Hardening_13.jpg\" alt=\"Hardening_13.jpg\"><\/li><li>You may need to restart Windows Server to apply the changes.<\/li><\/ol>\n\n\n\n<p>Ref: <a href=\"https:\/\/www.namecheap.com\/support\/knowledgebase\/article.aspx\/9598\/38\/disabling-sslv3\/\">Disabling SSLv3 &#8211; SSL Certificates &#8211; Namecheap.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The best way is to have this done by a free tool called &#8220;IIS Crypto&#8221; from the Nartac Software. You can download the tool from here. https:\/\/www.nartac.com\/ Below, is a way to get this done manually. but it&#8217;s not recommended. SSLv3 is an obsolete protocol, the main attack vector on which, at the time of <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=4922\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[10,15],"tags":[1708,1709],"class_list":["post-4922","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-windows-servers","tag-disable-ssl-v3-windows-server","tag-disable-tls-1-0-on-windows-servers"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4922"}],"version-history":[{"count":1,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4922\/revisions"}],"predecessor-version":[{"id":4923,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4922\/revisions\/4923"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}