Any opinions expressed here are my own and not necessarily those of my employer (I'm self-employed).

Sep 2, 2010

Hardening Windows Server 2003 SSL/TLS configuration

Though Windows Server 2003 has been around for a while, we'll still see them around the Internet for many years to come. Despite their usefulness, there are some important security considerations to make when running an Internet facing 2003 server.

SSL/TLS and the 2003 server
Windows Server 2003 was developed in a different era in terms of both security threats and the maturity of software security practices. In 2002, Bill Gates distributed his note on trustworthy computing internally at Microsoft. Since then Microsoft has made extensive efforts to produce more secure software — manifested in their SDL process. Among other tings, "secure by default" is an important principle in Microsoft's recent software. The 2003 server is not, so we'll discuss how to tighten up the SSL/TLS configuration. But first a quick primer on SSL/TLS.

The SSL/TLS protocols
SSL (Secure Sockets Layer), and its successor TLS (Transport Layer Security) are security protocols used to secure many types of Internet services, such as web, FTP, e-mail and so on. In their traditional use they ensure confidentiality and integrity for communication channel. SSL/TLS also offers server authentication in the most widely used setup. Find more information on the SSL/TLS protocols and their evolution on wikipedia.

SSL/TLS support is implemented in the schannel.dll in 2003 server. Many software packages rely on the native SSL/TLS support in Windows, e.g. Internet Explorer, the IIS (Microsoft's webserver software), and Google Chrome. It's therefore important to tighten up the SSL/TLS configuration.

To verify the current SSL/TLS configuration of a webserver, check out my previous blog post.

Disable weak encryption
A default configured 2003 server supports 40-bit encryption, and also the SSL 2.0 protocol. 40-bit encryption is subject to brute force attacks due to the short keylength. Why SSL 2.0 is supported is a mystery, as it was superseded by SSL 3.0 in 1996 due to critical security flaws.

Disabling the weak crypto requires registry changes, followed by a reboot. One can either take the tedious approach and edit the registry for hand, or the more efficient approach and put the required registry keys in a reg-file.

An example is included below, these are settings I have successfully loaded into registry on a Windows 2003 Server. A disclaimer is called for here, as editing the registry is not for the faint hearted. If something goes wrong the Windows installation might end up severely corrupted. Use the settings below at your own risk!

Copy the text (not including the horizontal lines), save it to a a file, e.g. sslsettings.reg, and double-click the file to load the settings into registry.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 128/128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server]

After the settings are loaded to registry, a reboot is required for the changes to take effect. That's it! Any attempt to setup a SSL/TLS connection using SSL 2.0 or weak encryption will fail.

Mitigate MitM vulnerability
In November 2009 a vulnerability facilitating a Man-in-the-Middle attack on the SSL/TLS protocols was disclosed. Microsoft discusses the issue in a security advisory: SSL/TLS MitM vulnerability. Being the single most important security protocol on the Internet, TLS needed an update. Since 2009, various SSL/TLS implementations have been updated. Finally, last month (August 2010) Microsoft released an update through their Microsoft Update. The update implements RFC 5746, which solves the problem.

Add stronger crypto?
Since the 2003 server does not support AES cipher suites, there have been some interoperability issues with other systems. To cope with this, Microsoft released a hotfix adding support for the AES cipher. However, as the changes included in the latest TLS update are considerable, I would not risk installing the AES hotfix. Instead, consider upgrading to the 2008 server instead!


  1. I tried to do this and now its screwed up my registry and now I cannot run Regedit to restore the backup registry as it will now not run regedit or even explorer , this is critical we cannot affor dto have this server be down

  2. Thanks for useful post. I also think you might be interested in topic on whatsapp spy apps.

  3. To get started, restart your computer and load the registry cleaner. registry repair

  4. In your life you need of free robux generator online for get free robux online

  5. This comment has been removed by the author.

  6. Your music is stunning. You have some extremely capable craftsmen. I wish you the best of accomplishment. system healer virus removal process

  7. card games solitaire has variety of online solitaire card games that are available on our website for download and also with the option to play online directly without downloading

  8. Get the best Assignment Help Australia  by the expert assignment writers at Make My Assignments. Our experts are fluent in writing assignments without missing the deadlines as they have earned their degrees from the renowned colleges and universities around the world.

  9. If you want to get good business research topic ideas then come at Students Assignment Help and meet all your needs. Our experts will make your experience best academic writings at a cheap price. We deliver all our work within the deadline.

  10. When you have discovered a window cleaner whether in London or anyplace else, you ought to dependably have the capacity to have your seals cleaned. best solar information online

  11. I am a content writer and editors at MyAssignmenthelp.co.uk. MyAssignmenthelp is a leading reputable dissertation help and writing services company in UK. MyAssignmenthelp provides best dissertation help, best dissertation writing services and best dissertation proposal writing service in UK. We have 4000+ professional academic writers. All writers of always updated, professional and experienced.

  12. Amazing website to peruse and share,each and each line in your blog is special and mind blowing exceptionally hard to compose such sort of article on the grounds that so much data is accessible on web and to discover great one among them is a troublesome undertaking.

    I invest hours on web and after an excessive amount of diligent work I arranged a blog which will shaken you mind on the off chance that you read it.please see my page:- What is Love

  13. As a student I prefer to read the blogs I am learning ASP.NET and I am on a beginner level and having difficulties while performing any task, I have a client's project https://vidnado.com.au and they need it on asp.net but I am struggling hard to achieve this task.

  14. Thank you so much for sharing this great blog.Very inspiring and helpful too. Hope you continue to share more of your ideas. I will definitely love to read. Assignment help online

  15. Such a nice blog post on this topic. According to the assignment experts, the next step will be to get the outline of the assignment help checked by the professor. This will help the experts to follow the project outline being given. Moreover, it will also reduce the risk of change in the outline after the completion of the assignment.

  16. Computer software is held in the storage of computers for a very specific purpose and performs the function of the program it implements, either by directly providing instructions to the computer hardware or by serving as an input to another piece of software.innovative apps in Modesto

  17. I admire people who keep sharing valuable stories through great writing. I'm glad to have read this blog. Thanks and hope to read more soon. Check out Lawrence Todd Maxwell's page to learn more about real estate.

  18. Thank you! I'm glad to find the information here.
    gmail email login

  19. The experts of this company always understand the students and their homework issues. So, they provide best primary homework help service in doing their assignment in numerous subjects. The service not only helps the students in resolving their issues of academic assignment, but also provides some time for meditation and relaxation.You can complete you academic study in much easier way with academic study assist from the best experts. Students just require stretching their hands asking for help in their assignments. The experts are always ready to provide best academic Study Help to help you in bringing A+ grade in your examination. Apart from feeding the students with ready assignments, the experts of this company also help them in writing their assignments by their own.

  20. Sample Assignment is one of those reliable academic websites from where you can get online help with assignment at the most affordable rates. Students can go through a huge list of full-length assignment samples which can be found on their website. This online assignment service provider has three teams who work together to produce and deliver high-quality assignments to the client’s doorstep. Customer care executives, subject experts, and the quality assurance team provide all kinds of university assignments such as dissertations, essays, reports, literature reviews, and more. We also have a 24-hour online assignment help service, which students can avail of via WhatsApp, Messenger, and email. Simply let us know your assignment’s requirements and our teams will bring you the best assignment help written by them.

  21. Thanks for providing such valuable information. There is one such company that goes by the name of Online Assignment Expert that caters to the needs of students in universities around the world. We provide Computer Science Assignment Help with our exceptional team of writers who are experts in their corresponding disciplines and cover numerous amounts of related topics.

    You can do a lot by efficiently delivering java programming assignment help that is a part of the discipline of computer science. Our value-added services cover one-to-one sessions with the experts of python assignment help, proofreading, and quality checking free of cost! Moreover, assignments written by us are plagiarism-free provided with a set of Turnitin report. We guarantee 100% customer satisfaction through our services. Contact our services now!

  22. This is a very great post and the way you express your all post details that is too good. Stressed with the approaching deadline of your Assignment work? Having sleepless nights? Give all your worries to the genius experts of CMA anytime. Australia assignment writing services.

  23. Great suggestions! I have truly enjoyed surfing around your blog posts. Just continue composing this kind of post. Recently I found one of a good website for Free Tarot Guide for Future . Hope you would like this too.


  24. Many of the people are depressed about the problems of essay writing. Well, don’t worry about that because we are providing this service at a very reasonable price.
    Do My Homework
    Do My Assignment

  25. I loved the article, keep updating interesting articles. I will be a regular reader I am offering assignment help to students over the globe at a low price.
    Article Assignment Help
    Essay Assignment Helper
    Essay writing
    Essay writing service
    Dissertation help
    Thesis writing help
    Write My Essay
    Do My Essay
    Hire Cheap Essay Writer
    College Essay Help

  26. Thanks for sharing this information. I have shared this link with other keep posting such information to provide best in class law assignment help online at very affordable prices.
    Assignment Help
    Assignment Helper
    Essay writing
    Essay writing service
    Dissertation help
    Thesis writing help
    Write My Essay
    Computer Science Assignment Help
    Assignment Help South Africa
    Assignment Writing Service

  27. Many of the people are depressed about the problems of essay writing. Well, don’t worry about that because we are providing this service at a very reasonable price.
    Essay Writer
    seo writing service
    Essay writing service
    Essay writing help
    Write My Essay
    hire seo writer
    hire writer
    Write my essay cheap
    hire article writer

  28. Sample Assignment is a renowned for assignment writing help and has assisted thousands of international students with their academics. Our dedicated team of experts has been providing full-fledged assignments to students pursuing their courses at various colleges and universities, and found to be avidly googling networking assignment help across the continent. While Australia is among the most preferred destinations for individuals from around the world, Assignment Experts has also won the trust of a vast pool of students here. The Australia Assignment help, such as Sample Assignment, can be easily contacted via WhatsApp and Messenger too. With our 24-hour online academic assistance, any student can reach out to us whenever he or she is in the need of help of a other subject expert like Psychology assignment help expert.

  29. StudentsAssignmentHelp.com is working with team of professional experts that is continue giving the best Thesis Help services. We know quality matters for students that is why all our work is original and free from any kind of plagiarism work. Thus save your precious time and stay relaxed.

  30. When tiworker.exe is causing high CPU use, you can simply fix it by following the steps below. Windows 10 users should press Windows Home button and search for 'Troubleshooting'. In the new window, look at the left side. After you go to View All, you should be able to locate 'System Maintenance'Windows Modules Installer Worker

  31. Brother Printers frequently indicate technical hitches because of inward reasons. There are numerous reasons which can cause Brother printer offline windows 10. Call us now to get a reliable solution.

  32. I would like to thank you for sharing with us interesting post.Career Predictions by Date of Birth

  33. AllAssignmentHelp reviewsAssignmentservicerating is best reviews site.We at Top Quality Assignment believe that there is no shortcut to success and to attain success, hard work, dedication, and commitment must be present. We are an online platform where students check & write reviews for assignments related websites.  

  34. Wow!! It's a really great experience shearing with us. I like your post, it's a really interesting.Monthly Horoscope by Date of Birth

  35. I found this one pretty fascinating and it should go into my collection. Very good work! I am Impressed. We appreciate that please keep writing more content. We are the assignment helper, we provide services all over the globe. We are best in these:- services
    How To Do Homework Fast
    how to write an assignment
    how to write an introduction for an assignment
    How to write an expository essay?
    what is python programming language and where it is used?
    What is the difference difference between java and java script?
    How to study for exams

  36. Many of the people are depressed about the problems of essay writing. Well, don’t worry about that because we are providing this service at a very reasonable price.
    Online Assignment Help Australia
    5 effective database assignment ideas
    psychology assignment help
    6 Benefits of Meditation to Students
    Best Statics Assignment Help
    Best Assignment Help

  37. Once you request for our Best Custom Essay Services our writers use a guide in creating your assignments. Each paper is crafted from scratch to guarantee plagiarism free work. Whether you have a topic in mind or require help in choosing the most suitable topic, Buy Pre Written Essays can help get your paper completed.


  38. find the best partner with Best free dating apps CrazyKrush app, currently, this is best dating app

  39. Amazing article you have written a lot of information. Appreciate your point of view and please keep continue posting.
    Listen, share and download the trending
    Fakaza Music,
    fakaza music download 
    fakaza mp3 download 2019,
    fakaza news,
    fakaza music download 2019.
    fakaza mp3 ,
    fakaza mag. Libraries are also updated daily with
    fakaza com!
    fakaza amapiano 2019,
    fakaza 2019,
    fakaza wap

  40. Thanks for this valuable information sharing, and i learned a lot and cleared my all doubts in this.. keep posting like this useful information.
    post free classified ads in india

  41. Thanks for this valuable information sharing, and i learned a lot and cleared my all doubts in this.. keep posting like this useful information.
    Scaffolding Dealers in Chennai
    Aluminium Scaffolding Dealers in Chennai

  42. Thanks for sharing this wonderful information. I hope you will share more helpful information regarding the content.
    web portal development company in chennai

  43. Where to find a Best Kitchen Knife >>
    Best Kitchen Knife in India
    Top 10 Best Mixer Grinders in India with Price ::
    Best Mixer Grinder in India
    Top Best Refrigerators ::
    Best Refrigerators in India
    Get Ready for Breakfast with Sandwich Makers :
    Best Sandwich Maker
    Best Kitchen Chimneys in India >>
    Best Kitchen Chimney

  44. Thanks for sharing this wonderful information. I hope you will share more helpful information regarding the content.
    scaffolding dealers in chennai
    aluminium scaffolding dealers in chennai

  45. When you have a reliable Nursing Papers for Sale company, you only expect to obtain high-quality Nursing Research Paper that have been written according to your instructions.

  46. you might be a great author.I will make certain to bookmark your blog and will eventually come back later.

  47. Seek Aid is the best ngo all over the world working for improving the lives of causes affected people through better education, health care, and economic opportunities, as well as providing emergency aid in natural disasters, war, and other conflicts. Please come forward and contribute. Your contribution will transform the lives of millions of peoples.

  48. I am glad that I saw this post. It is informative blog for us and we need this type of blog thanks for share this blog, Keep posting such instructional blogs and I am looking forward for your future posts.
    Cyber Security Projects for Final Year

    JavaScript Training in Chennai

    Project Centers in Chennai

    JavaScript Training in Chennai

  49. تنظيف الخزانات صعبة الوصول يمكن تنظيف خزان المياه المنزلي الذي يصعب الوصول إليه عن طريق اتباع الخطوات الآتية:[١] ملء الخزان بالمياه، والتأكد من امتلائه بها. وضع كمية من المبيض المستخدم في المنزل في الخزان، وذلك حسب سعته؛ حيث يجب وضع كوب من المبيض للخزان الذي تبلغ سعته 277 لتراً، وكوبين للخزان الذي تبلغ سعته 455 لتراً، وهكذا. ترك المحلول في الخزان مدة 12 ساعة مع عدم استعمال الماء. تفريغ الخزان للتخلص من المياه بشكل كامل. ملء الخزان بمياه نظيفة.

    شركة عزل خزانات بالرس
    شركة عزل خزانات بسكاكا
    شركة عزل خزانات بالدوادمي
    شركة عزل خزانات بالزلفي

    South African house music is known for its ability to constantly reinvent

    itself. And 2018 has been no different. A new sound which is known as amapiano

    is a mix of deep house, gqom all mixed in with the jazzy,soulful sound of a

    piano.of Born in Soweto, a homegrown label which backed AmaPiano since its

    early days, Initially, Amapiano was a confined success in the townships,

    playing in.
    VIGRO DEEP mp3 song download
    Mission ft. V. Rose mp3 song downloader
    Zing Master – Mara Jolang mp3 song downloader
    Dj Snowboy mp3 song downloader
    TNS mp3 song downloader
    Dj ice flake & DJ FeezoL mp3 song downloader
    guguletu(pro tees) rebass mp3 song downloader
    maxy songs datafilehost mp3 song downloader
    haka matorokisi mp3 song downloader
    dj goldex iwalk yephara song downloader
    amapiano 2019 mix mp3 song downloader
    nestro da producer – muscle science ep mp3 song downloader
    unjoko sengiqomile mp3 song downloader
    master kg nomcebo kokota mp3 song downloader
    sjava umama mp3 song
    Fakaza Music
    fakaza mp3 download 2019
    fakaza music download 2020
    Gqom is a genre of electronic dance music that emerged in the early 2010s from

    Durban, South Africa. It developed out of South African house music, kwaito

    techno. Unlike other South African electronic music, gqom is typified by

    minimal, raw and repetitive sound with heavy bass beats but without the four-

    on-the-floor rhythm pattern.

  51. Definitely one of the most detailed and well written guides I could find. Thanks a lot!


Copyright notice

© André N. Klingsheim and www.dotnetnoob.com, 2009-2018. Unauthorized use and/or duplication of this material without express and written permission from this blog’s author and/or owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to André N. Klingsheim and www.dotnetnoob.com with appropriate and specific direction to the original content.

Read other popular posts