Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To manage TLS 1.2 permissions requires intimate knowledge of the registry. See these Microsoft articles for more information: https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings and https://docs.microsoft.com/en-US/troubleshoot/windows-server/windows-security/restrict-cryptographic-algorithms-protocols-schannel To simplify the management of these settings, we use the program IIS Crypto from Nartec Software at Tricerat and it makes managing these security settings as easy as clicking a button. See their documentation here https://www.nartac.com/Products/IISCrypto for a complete description. We recommend using the Best Practices button. Make sure you understand the TLS/SSL requirements of other software you may use as because weak protocols may be disabled by IIS Crypto best practices.

Info

The specific cipher required for ScrewDrivers v7.0.0 through v7.6.0 is TLS_RSA_WITH_AES_256_CBC_SHA

Info

The specific cipher required for ScrewDrivers v7.7.0 is TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

When making changes, a reboot is always necessary before updated settings are applied!

Infonote

A good recommended practice is to always backup the registry before making changes!

...

See the Advanced tab and the Backup Registry button in IIS Crypto.