Deactivating RC4 on IIS
RC4 is a stream cipher for bulk encryption that nowadays is considered as practically vulnerable and was officially deprecated by Internet Engineering Task Force.
- Open registry editor:
Win + R >> regedit
- Navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\Schannel\Ciphers
- Right-click on Ciphers >> New >> Key
data:image/s3,"s3://crabby-images/6f65f/6f65f4698a83edbe02c0d516499af6486be3aa9d" alt="Hardening_14.jpg"
Name the key 'RC4 40/128'
- Right-click on RC4 40/128 >> New >> DWORD (32-bit) Value
data:image/s3,"s3://crabby-images/6c3d8/6c3d8f88fa8bf062e3ac79744bad3a6b1a9f8657" alt="Hardening_15.jpg"
Name the value 'Enabled'
- Double-click the created Enabled value and make sure that there is zero (0) in Value Data: field >> click OK
data:image/s3,"s3://crabby-images/45384/45384538501a6a0dcfbdf9bb14bd3123bc58a264" alt="Hardening_16.jpg"
- Create two more keys with the names 'RC4 56/128' and 'RC4 128/128' in the Ciphers directory. Repeat steps 4 and 5 for each of them.
- After step 6 is completed, you should have three keys for RC4 in total in Ciphers. Each RC4 key should have the DWORD value named 'Enabled' with zero (0) value data.
data:image/s3,"s3://crabby-images/475e6/475e620962e96934d4af257a87742c478ac23930" alt="Hardening_17.jpg"
- You may need to restart Windows Server to apply the changes.