UCF STIG Viewer Logo

The Internet Explorer SSL/TLS parameter must be set correctly.


Overview

Finding ID Version Rule ID IA Controls Severity
V-6238 DTBI014 SV-6288r3_rule ECSC-1 Medium
Description
This parameter ensures SSL and TLS are able to be used from the browser.
STIG Date
Microsoft IE Version 6 2014-12-17

Details

Check Text ( C-198r6_chk )
Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Verify a check mark is placed in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. If so, this is acceptable and not a finding. Verify there is not a check placed in the check box for 'Use SSL 2.0'. If 'Use SSL 2.0' is checked, then this is a finding.
Fix Text (F-154r5_fix)
Fix Text:
Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Place a check mark in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. Uncheck 'Use SSL 2.0' option.