IIS Server Security - IIS SMTP TLS with 256 bit encryption on IIS 6 [repost]

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > August 2005 > IIS SMTP TLS with 256 bit encryption on IIS 6 [repost]





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author IIS SMTP TLS with 256 bit encryption on IIS 6 [repost]
FastEddie

2005-08-04, 5:59 pm

All,

Is there a way to make Windows 2003 IIS 6 support 256 bit TLS? As far as I
have read, IIS6 does not support it. I really need this up and running ASAP!
Do I need to use Apache to do this?

If there is a way for IIS 6, please follow up with info and links if
possible.

Thanks,

FastEddie


John Banes

2005-08-05, 2:49 am

I assume you're talking about one of the 256-bit AES cipher suites that have
been defined for use with the TLS protocol? These are not currently
supported by the TLS implementation that's integrated into Windows, and as
such these cipher suites are not currently supported by IIS nor by IE. This
situation may change at some point in the future, but I have no idea as to
when. I mean, it's not like I work for Microsoft or anything. :-)

Why do you require this feature, anyway? In the application threat models
that I've seen, the vulnerability of 128-bit encryption is typically nowhere
near the top of the list. If you were to elaborate a little bit, then you
might obtain a more useful answer, either from me or someone else...

Please feel free to restrict all further responses to this thread to the
microsoft.public.security.crypto newsgroup, as that's the one most relevant
to this subject.

Regards,
John



"FastEddie" <fasteddie@therockwells.net.no.spam> wrote in message
news:OwFVR6PmFHA.3936@TK2MSFTNGP10.phx.gbl...
> All,
>
> Is there a way to make Windows 2003 IIS 6 support 256 bit TLS? As far as I
> have read, IIS6 does not support it. I really need this up and running
> ASAP!
> Do I need to use Apache to do this?
>
> If there is a way for IIS 6, please follow up with info and links if
> possible.
>
> Thanks,
>
> FastEddie
>



jonathan.lampe@standardnetworks.com

2005-08-26, 5:59 pm

See also:
http://www.microsoft.com/technet/co...c=en-us&m=1&p=1

One of the reasons some of us are hoping for AES in Microsoft SSL is that
people (often competitors) are starting to knock (with good reason) Microsoft
SSL as being behind the curve. Almost all major SSL implementations
including those from Sun, OpenSSL and many other commercial SSL stacks for
Windows already include AES support. When people figure out that Microsoft
SSL lacks the AES algorithm, it usually comes as a surprise.

One of the other reasons some of us are hoping for AES in Microsoft SSL is
that it a FIPS 140 approved algorithm. Several years ago my company ended up
writing an AES library (that subsequently earned FIPS 140-2 validation)
because we couldn't wait for Microsoft to implement AES and get it approved.
Now that Microsoft finally has a FIPS-validated AES module, we're stuck
waiting for them to implement it in SSL so people who are stuck with 3DES as
their only FIPS-approved algorithm can move to something better.

(Feel free to kick me a private response at
"jonathan.lampe@standardnetworks.com" too.)

"FastEddie" wrote:

> All,
>
> Is there a way to make Windows 2003 IIS 6 support 256 bit TLS? As far as I
> have read, IIS6 does not support it. I really need this up and running ASAP!
> Do I need to use Apache to do this?
>
> If there is a way for IIS 6, please follow up with info and links if
> possible.
>
> Thanks,
>
> FastEddie
>
>
>

Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com