Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6238 | DTBI014 | SV-6288r3_rule | ECSC-1 | Medium |
Description |
---|
This parameter ensures SSL and TLS are able to be used from the browser. |
STIG | Date |
---|---|
Microsoft IE Version 6 | 2014-07-03 |
Check Text ( C-198r6_chk ) |
---|
Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Verify a check mark is placed in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. If so, this is acceptable and not a finding. Verify there is not a check placed in the check box for 'Use SSL 2.0'. If 'Use SSL 2.0' is checked, then this is a finding. |
Fix Text (F-154r5_fix) |
---|
Fix Text: Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Place a check mark in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. Uncheck 'Use SSL 2.0' option. |