1. Home
  2. Security Hardening
  3. DISA IIS 8.5 Site V2R1
  4. IISW-SI-000204 – A public IIS 8.5 website must only accept Secure Socket Layer connections when authentication is required.

IISW-SI-000204 – A public IIS 8.5 website must only accept Secure Socket Layer connections when authentication is required.

Details

Transport Layer Security (TLS) encryption is a required security setting for a private web server. Encryption of private information is essential to ensuring data confidentiality. If private information is not encrypted, it can be intercepted and easily read by an unauthorized party. A private web server must use a FIPS 140-2-approved TLS version, and all non-FIPS-approved SSL versions must be disabled.

NIST SP 800-52 specifies the preferred configurations for government systems.

Solution

Note: If the server being reviewed is a private IIS 8.5 web server, this is Not Applicable.

Note: If the server is hosting WSUS, this is Not Applicable.

Follow the procedures below for each site hosted on the IIS 8.5 web server:

Open the IIS 8.5 Manager.
Click the site name.
Double-click the ‘SSL Settings’ icon.
Select ‘Require SSL’ check box.
Select ‘Apply’ from the ‘Actions’ pane.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles