Rex IT Blog

2020年2月18日 星期二

CryptoAPI Cryptographic Service Providers

https://docs.microsoft.com/en-us/windows/win32/seccertenroll/cryptoapi-cryptographic-service-providers


Cryptographic Provider Names
https://docs.microsoft.com/zh-tw/windows/win32/seccrypto/cryptographic-provider-names
Rex Huang 於 晚上9:45 沒有留言:

IIS Crypto is a free tool that gives administrators the ability to enable or disable protocols, ciphers, hashes and key exchange algorithms on Windows Server

https://www.nartac.com/Products/IISCrypto

REF:
https://cheyi.idv.tw/wp/2019/08/16/insufficient-diffie-hellman-strength/
Rex Huang 於 晚上8:58 沒有留言:

指定 TLS 伺服器預設的 Diffie-hellman Helman 金鑰位長度,請建立ServerMinKeyBitLength


解釋:
DWORD是Unsigned integer (32-bit),0x00000800就是2048位元,1024被認為不安全

REF:
https://docs.microsoft.com/zh-tw/windows-server/security/tls/tls-registry-settings
https://thycotic.force.com/support/s/article/TLS-Diffie-Hellman-Hardening
KB3174644
https://docs.microsoft.com/en-us/security-updates/SecurityAdvisories/2016/3174644
Weak Diffie-Hellman and the Logjam Attack
https://weakdh.org
Rex Huang 於 晚上8:54 沒有留言:
‹
›
首頁
查看網路版
技術提供:Blogger.