Score:1

Adding Ciphers to Server 2012 R2

us flag

I need to add the following Ciphers to my server:

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

I found the following article: https://docs.microsoft.com/en-us/windows-server/security/tls/manage-tls

However, it's not too clear to me. The list I get from the "SSL Cipher Suites" field contains 39+ Ciphers and is A LOT longer than the allowed 1023 characters. While in actuality when I test my explorer11 browser against ssllabs I get only 16.

djdomi avatar
za flag
Applies to: Windows Server (Semi-Annual Channel), Windows Server 2016, Windows 10 means your out of scope with 2012
cn flag
If the list is longer than 1023 characters, group policy cannot be used to manage this setting. Check the value in the registry, and also using a tool like IISCrypto will show you the current registry values.
cm flag
+1 for IISCrypto - just manage your TLS settings with this.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.