IIS8 预防SSL降级攻击


Secure Renegotiation  (Client-initiated) VULNERABLE (DoS)

微软官方文档

https://support.microsoft.com/zh-cn/help/980436/ms10-049-vulnerabilities-in-schannel-could-allow-remote-code-execution

 

需要修改注册表

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL

下表显示了这些 DWORD 值的用法:

DWORD Value = zero Value = nonzero
AllowInsecureRenegoClients 严格服务器 兼容服务器
AllowInsecureRenegoServers 严格客户端 兼容客户端
免备案空间专题