STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Instance Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

Confidentiality of information during transmission must be controlled through the use of an approved TLS version.

DISA Rule

SV-271310r1111062_rule

Vulnerability Number

V-271310

Group Title

SRG-APP-000175-DB-000067

Rule Version

SQLI-22-008300

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Important Note: Incorrectly modifying the Windows Registry can result in serious system errors. Before making any modifications, ensure there is a recent backup of the system and registry settings.

Access the SQL Server.
Access an administrator command prompt.
Type "regedit" to launch the Registry Editor.

Enable TLS 1.2:

1. Navigate to the path HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.
a. If the "TLS 1.2" key does not exist, right-click "Protocols".
b. Click "New".
c. Click "Key".
d. Type the name "TLS 1.2".

2. Navigate to the "TLS 1.2" subkey.
a. If the subkey "Client" does not exist, right-click "TLS 1.2".
b. Click "New".
c. Click "Key".
d. Type the name "Client".
e. Repeat steps A-D for the "Server" subkey.

3. Navigate to the "Client" subkey.
a. If the value "Enabled" does not exist, right-click on "Client".
b. Click "New".
c. Click "DWORD".
d. Enter "Enabled" as the name.
e. Repeat steps A-D for the value "DisabledByDefault".

4. Double-click "Enabled".

5. In Value Data, enter "1".

6. Click "OK".

7. Double-click "DisabledByDefault".

8. In Value Data, enter "0".

9. Click "OK".

10. Repeat steps 3-9 for the "Server" subkey.

Disable unwanted SSL/TLS protocol versions:

1. Navigate to the path HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.
a. If the "TLS 1.0" key does not exist, right-click "Protocols".
b. Click "New".
c. Click "Key".
d. Type the name "TLS 1.0".

2. Navigate to the "TLS 1.0" subkey.
a. If the subkey "Client" does not exist, right-click "TLS 1.0".
b. Click "New".
c. Click "Key".
d. Type the name "Client".
e. Repeat steps A-D for the "Server" subkey.

3. Navigate to the "Client" subkey.
a. If the value "Enabled" does not exist, right-click on "Client".
b. Click "New".
c. Click "DWORD".
d. Enter "Enabled" as the name.
e. Repeat steps A-D for the value "DisabledByDefault".

4. Double-click "Enabled".

5. In Value Data, enter "0".

6. Click "OK".

7. Double-click "DisabledByDefault".

8. In Value Data, enter "1".

9. Click "OK".

10. Repeat steps 3-9 for the "Server" subkey.

11. Repeat steps 1-10 for "TLS 1.1", "SSL 2.0", and "SSL 3.0".

Check Contents

Access the SQL Server.
Access an administrator command prompt.
Type "regedit" to launch the Registry Editor.

Navigate to:
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2

If this key does not exist, this is a finding.

Verify a REG_DWORD value of "0" for "DisabledByDefault" and a value of "1" for "Enabled" for both Client and Server.

Navigate to:
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0

Under each key, verify a REG_DWORD value of "1" for "DisabledByDefault" and a value of "0" for "Enabled" for both Client and Server subkeys.

If any of the respective registry paths are non-existent or contain values other than specified above, this is a finding. If Vendor documentation supporting the configuration is provided, reduce this finding to a CAT III.

Vulnerability Number

V-271310

Documentable

False

Rule Version

SQLI-22-008300

Severity Override Guidance

Access the SQL Server.
Access an administrator command prompt.
Type "regedit" to launch the Registry Editor.

Navigate to:
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2

If this key does not exist, this is a finding.

Verify a REG_DWORD value of "0" for "DisabledByDefault" and a value of "1" for "Enabled" for both Client and Server.

Navigate to:
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0

Under each key, verify a REG_DWORD value of "1" for "DisabledByDefault" and a value of "0" for "Enabled" for both Client and Server subkeys.

If any of the respective registry paths are non-existent or contain values other than specified above, this is a finding. If Vendor documentation supporting the configuration is provided, reduce this finding to a CAT III.

Check Content Reference

M

Target Key

5677