<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Enforcing SSL 3.0 and removing weak encryption vulnerability over SSL ( IIS 6.0 and ISA )</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx</link><description>Running a Custom Penetration test&amp;#160; on IIS 6.0 server having SSL enabled may show vulnerability reports as a weak encryption on IIS . ISA server 2000 acts as&amp;#160; proxy in front of the IIS server and also has certificate installed on it. The following</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>re: Enforcing SSL 3.0 and removing weak encryption vulnerability over SSL ( IIS 6.0 and ISA )</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx#3436561</link><pubDate>Thu, 01 Oct 2009 23:52:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:3436561</guid><dc:creator>sathai</dc:creator><description>&lt;p&gt;This help me on the PCI test, Thanks.&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=3436561" width="1" height="1"&gt;</description></item><item><title>re: Enforcing SSL 3.0 and removing weak encryption vulnerability over SSL ( IIS 6.0 and ISA )</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx#2999957</link><pubDate>Wed, 11 Mar 2009 15:30:10 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2999957</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Very interesting artilce&lt;/p&gt;
&lt;p&gt;Im not very familiar in cryptography but I received some questions about a customer, so Im trying to get up to speed...&lt;/p&gt;
&lt;p&gt;My questions is, in IIS6, if &amp;nbsp;we install a Certificat that is Version3 (SHA-1, RSA1024,..), do we still need to perform Registry &amp;nbsp;changes ?&lt;/p&gt;
&lt;p&gt;Thks&lt;/p&gt;
&lt;p&gt;jc&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2999957" width="1" height="1"&gt;</description></item><item><title>re: Enforcing SSL 3.0 and removing weak encryption vulnerability over SSL ( IIS 6.0 and ISA )</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx#2997903</link><pubDate>Tue, 10 Mar 2009 23:45:11 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2997903</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Yes, if you go to &lt;a rel="nofollow" target="_new" href="http://www.serversniff.net"&gt;http://www.serversniff.net&lt;/a&gt;, you can use their free tool to check the web server:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.serversniff.net"&gt;http://www.serversniff.net&lt;/a&gt;/content.php?do=ssl&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2997903" width="1" height="1"&gt;</description></item><item><title>re: Enforcing SSL 3.0 and removing weak encryption vulnerability over SSL ( IIS 6.0 and ISA )</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx#2985942</link><pubDate>Thu, 05 Mar 2009 21:50:04 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2985942</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;I have made the registry changes as required and rebooted the server.&lt;/p&gt;
&lt;p&gt;If I then test it using a browser with only SSL 2.0 Enabled, I can still get to the web site (over HTTPS). Based on this test, the registry change had no effect.&lt;/p&gt;
&lt;p&gt;Is this not a valid method of testing?&lt;/p&gt;
&lt;p&gt;Is there a tool I can use to verify what level of SSL the server is requiring? &lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2985942" width="1" height="1"&gt;</description></item><item><title>https:// proxy server | Digg hot tags</title><link>http://blogs.iis.net/sakyad/archive/2008/12/11/enforcing-ssl-3-0-and-removing-weak-encryption-vulnerability-over-ssl-iis-6-0-and-isa.aspx#2803435</link><pubDate>Fri, 12 Dec 2008 06:44:04 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2803435</guid><dc:creator>https:// proxy server | Digg hot tags</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;https:// proxy server | Digg hot tags&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2803435" width="1" height="1"&gt;</description></item></channel></rss>