Re: SBS and SSL v.3.0

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



don't know know what they are thinking. Don't use firefox or Apache. Not familiar with Qualys or Nessus

--
Cris Hanna [SBS-MVP]
--------------------------------------
Please do not respond directly to me, but only post in the newsgroup so all can take advantage
"SteveB" <swb_mct@xxxxxxx> wrote in message news:Oc7zmEtmGHA.4212@xxxxxxxxxxxxxxxxxxxxxxx
Then what are they thinking when they recommend SSL v3.0 ?? Where is it supported? Apache, Firefox ?
"Cris Hanna (SBS-MVP)" <crisnospamhanna@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:eup5a3smGHA.1488@xxxxxxxxxxxxxxxxxxxxxxx
IE 7.0 supports SSL 3.0 IE 7.0 is still in beta and there are issues in using IE 7.0 with certain SBS features
I would suspect (and its only my opinion) that it may take IIS 7.0 which will come with Windows Server (Longhorn)

--
Cris Hanna [SBS-MVP]
--------------------------------------
Please do not respond directly to me, but only post in the newsgroup so all can take advantage
"SteveB" <swb_mct@xxxxxxx> wrote in message news:uyFE4TsmGHA.3596@xxxxxxxxxxxxxxxxxxxxxxx
When you run either of the two leading vulnerability scanners (Qualys or
Nessus) against any Microsoft server including SBS2003, you get the
recommendaton to upgrade to SSL v.3.0. because of specific flaws in SSL v2.
Is this a simple option to enable in IIS and is it automatically supported
in Internet Explorer.

I can't find it in IIS.

I am not asking for an assessment of it's importance . . .Banks are scanned
by one of these two scanners frequently in response to regulation, and they
run a closed system of Servers and Clients with SSL. If it just a matter of
clicking a couple of boxes, they could eliminated this reported
vulnerabiity.

Thanks



Relevant Pages

  • Re: SBS and SSL v.3.0
    ... Given that I don't surf at the server in the first place...why do they recommend this when you shouldn't be surfing there anyway? ... Cris Hanna (SBS-MVP) wrote: ... Then what are they thinking when they recommend SSL v3.0 ?? ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS and SSL v.3.0
    ... Cris Hanna (SBS-MVP) wrote: ... Then what are they thinking when they recommend SSL v3.0 ?? ... I would suspect that it may take IIS ...
    (microsoft.public.windows.server.sbs)
  • Re: External IP and OWA SSL
    ... Thanks - at the risk of asking a dumber question, can I use OWA with SSL ... > Cris Hanna (SBS-MVP) ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Encryption Level of web site
    ... SSL cipher checks work in nessus. ... > Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ... > about an hour, with no client, server changes, or ongoing maintenance. ...
    (Security-Basics)
  • Re: CSM 502 port errors
    ... Kevin Weilbacher [SBS-MVP] ... "The days pass by so quickly now, the nights are seldom long" ... Several people in this NG do not see a need for using SSL with Trend. ...
    (microsoft.public.windows.server.sbs)