Re: SBS and SSL v.3.0

Tech-Archive recommends: Fix windows errors by optimizing your registry



Then what are they thinking when they recommend SSL v3.0 ?? Where is it supported? Apache, Firefox ?
"Cris Hanna (SBS-MVP)" <crisnospamhanna@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:eup5a3smGHA.1488@xxxxxxxxxxxxxxxxxxxxxxx
IE 7.0 supports SSL 3.0 IE 7.0 is still in beta and there are issues in using IE 7.0 with certain SBS features
I would suspect (and its only my opinion) that it may take IIS 7.0 which will come with Windows Server (Longhorn)

--
Cris Hanna [SBS-MVP]
--------------------------------------
Please do not respond directly to me, but only post in the newsgroup so all can take advantage
"SteveB" <swb_mct@xxxxxxx> wrote in message news:uyFE4TsmGHA.3596@xxxxxxxxxxxxxxxxxxxxxxx
When you run either of the two leading vulnerability scanners (Qualys or
Nessus) against any Microsoft server including SBS2003, you get the
recommendaton to upgrade to SSL v.3.0. because of specific flaws in SSL v2.
Is this a simple option to enable in IIS and is it automatically supported
in Internet Explorer.

I can't find it in IIS.

I am not asking for an assessment of it's importance . . .Banks are scanned
by one of these two scanners frequently in response to regulation, and they
run a closed system of Servers and Clients with SSL. If it just a matter of
clicking a couple of boxes, they could eliminated this reported
vulnerabiity.

Thanks



Relevant Pages

  • Re: OWA - changing passwords
    ... Install and configure Secure Socket Layer (SSL) on the server. ... Set Up an HTTPS Service in IIS ...
    (microsoft.public.exchange.admin)
  • Re: Security of IIS - Secure Intranet web site on SBS2003 box
    ... > take two days to rebuild their server and return everything to normal. ... > Before 'Code Red' IIS was considered reasonably secure. ... >> over HTTP via SSL for OUTLOOK-EXCHANGE links to users operating in the ...
    (microsoft.public.windows.server.sbs)
  • Re: Web service deployment security
    ... The problem is that the IIS server machine which I use for tests is not from ... the Windows "server" family so I don't have the Certificate Server. ... Is there another way to get a certificate to test SSL connection? ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: SBS 2003 SP1 Exchange 2003 SP2 cant ActiveSync
    ... First you need to make sure that the directory structure in IIS has the ... correct permissions for OMA, OWA, and Activesync. ... I have tried without SSL and still no ... >> server, and Sprints EVDO data service uses a proxy to ...
    (microsoft.public.pocketpc.activesync)
  • Re: OWA works internally but not externally?
    ... I feel the problem is with SSL. ... 500 Internal Server Error - The network logon failed. ... I also noticed these errors in the event log of the server that host IIS & ... > 60> Microsoft Online Support Engineer ...
    (microsoft.public.exchange2000.general)