Install IIS Crypto to disable Weak Ciphers and Protocols
Last updated
Was this helpful?
Last updated
Was this helpful?
For the best possible security, we recommend disabling weak ciphers and protocols. To achieve this, download the free application IIS Crypto GUI: https://www.nartac.com/Products/IISCrypto/Download
Note! If other applications run on the same IIS, they may be negatively affected by the actions mentioned in this section!
Run the executable IISCrypto.exe and select the tab Cipher Suites.
Select the button Best Practices and click Apply.
We recommend (for details, see https://docs.microsoft.com/en-us/security/engineering/solving-tls1-problem) to disable the use of TLS 1.0 & TLS 1.1 protocol and enable TLS 1.2:
and click Apply button.
Note: You need to reboot your server for the changes to take effect! Since a reboot is also necessary after installing the Unicode font (see further down), you can postpone the reboot until after that step.
To test the active cipher suites, use the testing tool available on: https://www.nartac.com/Products/IISCrypto/ at Test Your Site or https://www.ssllabs.com/ssltest/