• RSS
  • Twitter
  • FaceBook

Deb Shinder Blog RSS

All Blogs  »  Deb Shinder Blog  »  ISA Central  »  Blog article: Hardening SSL Cipher Strength and SSL Protocol Support on ISA Servers

Hardening SSL Cipher Strength and SSL Protocol Support on ISA Servers

In a little known KB article there are instructions on how to get Windows to use only secure SSL connections. OK, SSL is a security technology by default, but there are varying cipher strength that govern the relative security of an SSL connection.

You might think that because there is a checkmark in the ISA firewall’s configuration interface that forces 128-bit encryption, that there can’t be any other levels of encryption negotiated. This isn’t true, although it is true that the ISA firewall will not pass traffic that isn’t 128bit encrypted when you enable this option. The problem is that Windows will negotiate a low level before ISA has a chance to block it and it leads to false positives when pen testing the firewall.

What’s the solution? Disable support for lower level cipher strengths. Jason Jones does it again with a fantastic article on how to do this in his blog post at:

http://blog.msfirewall.org.uk/2008/10/hardening-ss...l.html

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Leave a Reply


Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!