SV-256841r890133_rule
V-256841
SRG-APP-000014
APCG-00-000010
CAT I
10
Consult Microsoft documentation and ensure the .Net Framework on Compliance Guardian servers is a version that supports TLS 1.2. Update if necessary.
Configure the Compliance Guardian servers to enable TLS 1.2 protocol only.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.
- Disable TLS 1.0, TLS 1.1, and any SSL protocols, if present.
Configure the Compliance Guardian servers to enable strong cryptography settings.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 and verify:
"SystemDefaultTlsVersions" = dword:00000001
"SchUseStrongCrypto" = dword:00000001
Check the .Net Framework version on Compliance Guardian servers.
- On servers where Compliance Guardian is installed, open "Registry Editor".
- Refer to the Microsoft document to verify the .Net Framework version supports TLS 1.2. The Microsoft Document URL is: https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/security/enable-tls-1-2-client#bkmk_net.
- .NET Framework 4.6.2 or later supports TLS 1.2 natively.
If the .Net Framework version doesn't support TLS 1.2, this is a finding.
Check the Compliance Guardian servers only have TLS 1.2 protocol enabled.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.
- Verify TLS 1.0, TLS 1.1, and any SSL protocols are not enabled.
If TLS 1.0, TLS 1.1, or any SSL protocols are enabled, this is a finding.
Check that Compliance Guardian servers have strong cryptography setting enabled.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319.
Verify "SystemDefaultTlsVersions" = dword:00000001 and "SchUseStrongCrypto" = dword:00000001, otherwise this is a finding.
V-256841
False
APCG-00-000010
Check the .Net Framework version on Compliance Guardian servers.
- On servers where Compliance Guardian is installed, open "Registry Editor".
- Refer to the Microsoft document to verify the .Net Framework version supports TLS 1.2. The Microsoft Document URL is: https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/security/enable-tls-1-2-client#bkmk_net.
- .NET Framework 4.6.2 or later supports TLS 1.2 natively.
If the .Net Framework version doesn't support TLS 1.2, this is a finding.
Check the Compliance Guardian servers only have TLS 1.2 protocol enabled.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.
- Verify TLS 1.0, TLS 1.1, and any SSL protocols are not enabled.
If TLS 1.0, TLS 1.1, or any SSL protocols are enabled, this is a finding.
Check that Compliance Guardian servers have strong cryptography setting enabled.
- On the Compliance Guardian servers, open "Registry Editor".
- Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319.
Verify "SystemDefaultTlsVersions" = dword:00000001 and "SchUseStrongCrypto" = dword:00000001, otherwise this is a finding.
M
5531