Welcome to MobyThreads.com!
FAQFAQ   SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log in/Register/PasswordLog in/Register/Password

Subject: How to disable SSL v2 support on IIS 6.0?

 
   Web Hosting and Web Master Forums (Home) -> IIS RSS
Related Topics:
(no subject) - Hi All, After an upgrade from a server (no domain) to a domain (active Win Server 2000) we are no longer able to debug on this server using VS.NET (local copy on the server). I suspect this has to do with

Subject: IIS 6 WWW service needs restarting - Take a look at 218464 and FrontPage Error Save Results Form (201799). It appears that both the 2000c and 2000d both are the result of the incorrect use of forms. Hope this helps. Bryan

Subject: CSS not updating (cache?) - I work in web design office and we have this issue where changes to the stop being shown in the testing browser. It begins working again after we reboot the server. This leads me to believe that the server is caching the..

SelfSSL Failed to build the subject name blob: 0x80092023 - Hi All, I hope this is the correct group. If not, please direct me. I installed SelfSSL from the IIS6 resource kit on my Windows 2003 R2 server and tried to create a At a command prompt, I typed in: /T

Subject: IIS SMTP rejects messages with encrypted Zip files - Windows Server 2003 SP1 IIS 6.0 Email with password protected zip files are always rejected with the following NDR: Action: failed Status: 5.5.0 smtp;550 5.5.0 Mail rejected for container policy reasons. ..
Next:  IIS: SBS 2003 and IIS bad password for Site Administration  
Author Message
Ray Yan

External


Since: Apr 03, 2007
Posts: 1



(Msg. 1) Posted: Tue Apr 03, 2007 5:02 pm
Post subject: Subject: How to disable SSL v2 support on IIS 6.0?
Archived from groups: microsoft>public>inetserver>iis (more info?)

Hi there,

We're running a website on a IIS6.0 / Windows2003 SP1 server, with a Thawte
web server certificate installed to enable HTTPS access. Now we want to force
client connections use SSL v3 or SLT 1.0 or SLT 1.1 or better, so we decided
to stop supporting SSL v2 on this server. But we wonder what we have to do to
achive this?

Many thanks in advance!

Ray

 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Steve Schofield

External


Since: Nov 26, 2006
Posts: 221



(Msg. 2) Posted: Tue Apr 03, 2007 8:58 pm
Post subject: Re: Subject: How to disable SSL v2 support on IIS 6.0? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

These are the instructions to disable SSL 2.0

http://support.microsoft.com/kb/187498

--

Thank you,

Steve Schofield
Windows Server MVP - IIS
ASPInsider Member - MCP

http://www.orcsweb.com/
Managed Complex Hosting
#1 in Service and Support

"Ray Yan" <RayYan DeleteThis @discussions.microsoft.com> wrote in message
news:41F01654-B51D-489C-8D84-E1E35AA770F1@microsoft.com...
> Hi there,
>
> We're running a website on a IIS6.0 / Windows2003 SP1 server, with a
> Thawte
> web server certificate installed to enable HTTPS access. Now we want to
> force
> client connections use SSL v3 or SLT 1.0 or SLT 1.1 or better, so we
> decided
> to stop supporting SSL v2 on this server. But we wonder what we have to do
> to
> achive this?
>
> Many thanks in advance!
>
> Ray
>

 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Steve Schofield

External


Since: Nov 26, 2006
Posts: 221



(Msg. 3) Posted: Tue Apr 03, 2007 9:59 pm
Post subject: Re: Subject: How to disable SSL v2 support on IIS 6.0? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Excellent! We have pushed to several windows 2003 boxes with no issues.

--

Thank you,

Steve Schofield
Windows Server MVP - IIS
ASPInsider Member - MCP

http://www.orcsweb.com/
Managed Complex Hosting
#1 in Service and Support

"Ray Yan" <RayYan.RemoveThis@discussions.microsoft.com> wrote in message
news:504E205E-21BC-4401-826A-883E0DA8E05A@microsoft.com...
> That's what I'm looking for!!! Thank you very much, Steve!!!
>
> Ray
>
> "Steve Schofield" wrote:
>
>> These are the instructions to disable SSL 2.0
>>
>> http://support.microsoft.com/kb/187498
>>
>> --
>>
>> Thank you,
>>
>> Steve Schofield
>> Windows Server MVP - IIS
>> ASPInsider Member - MCP
>>
>> http://www.orcsweb.com/
>> Managed Complex Hosting
>> #1 in Service and Support
>>
>> "Ray Yan" <RayYan.RemoveThis@discussions.microsoft.com> wrote in message
>> news:41F01654-B51D-489C-8D84-E1E35AA770F1@microsoft.com...
>> > Hi there,
>> >
>> > We're running a website on a IIS6.0 / Windows2003 SP1 server, with a
>> > Thawte
>> > web server certificate installed to enable HTTPS access. Now we want to
>> > force
>> > client connections use SSL v3 or SLT 1.0 or SLT 1.1 or better, so we
>> > decided
>> > to stop supporting SSL v2 on this server. But we wonder what we have to
>> > do
>> > to
>> > achive this?
>> >
>> > Many thanks in advance!
>> >
>> > Ray
>> >
>>
>>
 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Juan Carlos A

External


Since: Apr 17, 2007
Posts: 1



(Msg. 4) Posted: Tue Apr 17, 2007 9:14 am
Post subject: About disabling SSL v2 support [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I actually disabled SSL v2 suppport. How could I validate this change? There is any tool to validate this?

Thanks.


EggHeadCafe.com - .NET Developer Portal of Choice
http://www.eggheadcafe.com
 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Daniel Crichton

External


Since: Apr 21, 2006
Posts: 144



(Msg. 5) Posted: Tue Apr 17, 2007 5:26 pm
Post subject: Re: About disabling SSL v2 support [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Juan wrote on Tue, 17 Apr 2007 09:14:49 -0700:

> I actually disabled SSL v2 suppport. How could I validate this change?
> There is any tool to validate this?

You could disable TLS and SSL3 in IE, leaving only SSL2 enabled, and then
try to connect - it will fail if SSL2 is disabled.

Dan
 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
jbongran

External


Since: Apr 14, 2006
Posts: 9



(Msg. 6) Posted: Wed Apr 18, 2007 12:27 am
Post subject: Re: About disabling SSL v2 support [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Juan Carlos A wrote:
> I actually disabled SSL v2 suppport. How could I validate this
> change? There is any tool to validate this?
>
> Thanks.
>
>
> EggHeadCafe.com - .NET Developer Portal of Choice
> http://www.eggheadcafe.com

http://www.microsoft.com/downloads/details.aspx?FamilyID=cabea1d0-5a10...bc-83d4
 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Sam Owen

External


Since: Dec 13, 2007
Posts: 1



(Msg. 7) Posted: Thu Dec 13, 2007 12:43 pm
Post subject: How to disable SSL v2 support on IIS 6.0? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

on a unix based box...
On a command line, type:

openssl s_client -connect TARGET_IP:PORT_NUMBER -ssl2

Where TARGET_IP is the IP address of the host in question and PORT_NUMBER is the port listed in the scan report for this QID.

For mail servers (port 25 and others) which use START TLS, you will need to use: openssl s_client -connect 66.241.44.125:25 -ssl2 -starttls smtp

If the result is an SSL handshake error similar to the example below, the host is not vulnerable:

CONNECTED(00000003)
9216:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:226:

However, if the connection is established and a large amount of data is displayed including the SSLv2 handshake information similar to the example below, the issue was successfully reproduced.

SSL handshake has read 798 bytes and written 239 bytes
---
New, SSLv2, Cipher is DES-CBC3-MD5
Server public key is 1024 bit
SSL-Session:
Protocol : SSLv2
Cipher : DES-CBC3-MD5
Session-ID: F2922D03DA5689A5BE15F3C7A1004B2E
Session-ID-ctx:
Master-Key: 061F4A4851422C0CA55AE99B9DAAF56E4F3E2B4410B1E221
Key-Arg : C13A05C608CABE51
Krb5 Principal: None
Start Time: 1099423702
Timeout : 300 (sec)
Verify return code: 18 (self signed certificate)

EggHeadCafe - .NET Developer Portal of Choice
http://www.eggheadcafe.com
 >> Stay informed about: Subject: How to disable SSL v2 support on IIS 6.0? 
Back to top
Login to vote
Display posts from previous:   
   Web Hosting and Web Master Forums (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]