Enable TLS 1.2 in Windows Server 2012 running Exchange 2013 via IIS 8.0 Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) Come Celebrate our 10 Year Anniversary!How to enable TLS 1.1, 1.2 in IIS 7.5How to enable “Sleep” for Windows 2012 serverLync & TLS: Event 36874 - how to handle?No Burflags in registryExchange 2013 and TLS 1.1/1,2Separate TLS control for MSSQL & IISIs it possible to configure ARR to make TLS 1.2 outgoing connections in Server 2008 R2?TLS 1.2 client hello triggers TCP Reset from 2012 R2Enable TLS 1.2 Exchange 2010Setup Exchange 2013 Organization Relationship using TLS 1.2

Why aren't air breathing engines used as small first stages

Is there a documented rationale why the House Ways and Means chairman can demand tax info?

Is it true that "carbohydrates are of no use for the basal metabolic need"?

What makes black pepper strong or mild?

What does the "x" in "x86" represent?

Did Kevin spill real chili?

Bonus calculation: Am I making a mountain out of a molehill?

Is above average number of years spent on PhD considered a red flag in future academia or industry positions?

Do you forfeit tax refunds/credits if you aren't required to and don't file by April 15?

ListPlot join points by nearest neighbor rather than order

Why did the IBM 650 use bi-quinary?

How can I make names more distinctive without making them longer?

Did Xerox really develop the first LAN?

What are the pros and cons of Aerospike nosecones?

Does accepting a pardon have any bearing on trying that person for the same crime in a sovereign jurisdiction?

G-Code for resetting to 100% speed

How discoverable are IPv6 addresses and AAAA names by potential attackers?

Why is black pepper both grey and black?

"Seemed to had" is it correct?

Can inflation occur in a positive-sum game currency system such as the Stack Exchange reputation system?

How does a Death Domain cleric's Touch of Death feature work with Touch-range spells delivered by familiars?

What would be the ideal power source for a cybernetic eye?

Should I call the interviewer directly, if HR aren't responding?

When to stop saving and start investing?



Enable TLS 1.2 in Windows Server 2012 running Exchange 2013 via IIS 8.0



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
Come Celebrate our 10 Year Anniversary!How to enable TLS 1.1, 1.2 in IIS 7.5How to enable “Sleep” for Windows 2012 serverLync & TLS: Event 36874 - how to handle?No Burflags in registryExchange 2013 and TLS 1.1/1,2Separate TLS control for MSSQL & IISIs it possible to configure ARR to make TLS 1.2 outgoing connections in Server 2008 R2?TLS 1.2 client hello triggers TCP Reset from 2012 R2Enable TLS 1.2 Exchange 2010Setup Exchange 2013 Organization Relationship using TLS 1.2



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








5















I got some issues getting the TLS 1.2 protocol running on one of our Windows Server 2012 machines. I checked this using ssllabs.com by Qualys and also tested with a powershell script and the linux tool "cipherscan".



The server hosts one Exchange 2013 SP1 (CU4) Server, with IIS 8.0. The certificate used is issued by our company CA. Another Windows Server 2012 with the same Exchange 2013 SP1 (CU4) installation works perfectly with the same certificate.



As I could research Windows Server 2012 uses TLS 1.2 by default. However this setting can be configured using the registry:



HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"


Microsoft also mentions that this local group policy setting might help:



System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing


As this setting should be set inside the operating system Microsoft also recommends to enable TLS 1.2 usage in the Internet Options of Internet Explorer.



I tried all of these 3 options, but none worked for me. Just to make this clear. The server (not just the IIS Service) was rebooted serveral times after enabling each of the settings.



Most guides and Scripts (e.g. powershell) just set the corresponding keys in the registry. I don't know exactly what else I could try.



I hope that somebody got the clue where to enable this.










share|improve this question

















  • 1





    Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

    – YuKYuK
    Feb 16 '15 at 12:59











  • I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

    – Kevin
    Feb 16 '15 at 13:14






  • 2





    KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

    – YuKYuK
    Feb 16 '15 at 13:20











  • Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

    – Kevin
    Feb 16 '15 at 13:25







  • 1





    Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

    – Kevin
    Feb 16 '15 at 13:34

















5















I got some issues getting the TLS 1.2 protocol running on one of our Windows Server 2012 machines. I checked this using ssllabs.com by Qualys and also tested with a powershell script and the linux tool "cipherscan".



The server hosts one Exchange 2013 SP1 (CU4) Server, with IIS 8.0. The certificate used is issued by our company CA. Another Windows Server 2012 with the same Exchange 2013 SP1 (CU4) installation works perfectly with the same certificate.



As I could research Windows Server 2012 uses TLS 1.2 by default. However this setting can be configured using the registry:



HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"


Microsoft also mentions that this local group policy setting might help:



System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing


As this setting should be set inside the operating system Microsoft also recommends to enable TLS 1.2 usage in the Internet Options of Internet Explorer.



I tried all of these 3 options, but none worked for me. Just to make this clear. The server (not just the IIS Service) was rebooted serveral times after enabling each of the settings.



Most guides and Scripts (e.g. powershell) just set the corresponding keys in the registry. I don't know exactly what else I could try.



I hope that somebody got the clue where to enable this.










share|improve this question

















  • 1





    Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

    – YuKYuK
    Feb 16 '15 at 12:59











  • I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

    – Kevin
    Feb 16 '15 at 13:14






  • 2





    KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

    – YuKYuK
    Feb 16 '15 at 13:20











  • Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

    – Kevin
    Feb 16 '15 at 13:25







  • 1





    Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

    – Kevin
    Feb 16 '15 at 13:34













5












5








5








I got some issues getting the TLS 1.2 protocol running on one of our Windows Server 2012 machines. I checked this using ssllabs.com by Qualys and also tested with a powershell script and the linux tool "cipherscan".



The server hosts one Exchange 2013 SP1 (CU4) Server, with IIS 8.0. The certificate used is issued by our company CA. Another Windows Server 2012 with the same Exchange 2013 SP1 (CU4) installation works perfectly with the same certificate.



As I could research Windows Server 2012 uses TLS 1.2 by default. However this setting can be configured using the registry:



HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"


Microsoft also mentions that this local group policy setting might help:



System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing


As this setting should be set inside the operating system Microsoft also recommends to enable TLS 1.2 usage in the Internet Options of Internet Explorer.



I tried all of these 3 options, but none worked for me. Just to make this clear. The server (not just the IIS Service) was rebooted serveral times after enabling each of the settings.



Most guides and Scripts (e.g. powershell) just set the corresponding keys in the registry. I don't know exactly what else I could try.



I hope that somebody got the clue where to enable this.










share|improve this question














I got some issues getting the TLS 1.2 protocol running on one of our Windows Server 2012 machines. I checked this using ssllabs.com by Qualys and also tested with a powershell script and the linux tool "cipherscan".



The server hosts one Exchange 2013 SP1 (CU4) Server, with IIS 8.0. The certificate used is issued by our company CA. Another Windows Server 2012 with the same Exchange 2013 SP1 (CU4) installation works perfectly with the same certificate.



As I could research Windows Server 2012 uses TLS 1.2 by default. However this setting can be configured using the registry:



HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server
DWORD "DisabledByDefault" Value "0x00000000"
DWORD "Enabled" Value "0x00000001" or "0xffffffff"


Microsoft also mentions that this local group policy setting might help:



System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing


As this setting should be set inside the operating system Microsoft also recommends to enable TLS 1.2 usage in the Internet Options of Internet Explorer.



I tried all of these 3 options, but none worked for me. Just to make this clear. The server (not just the IIS Service) was rebooted serveral times after enabling each of the settings.



Most guides and Scripts (e.g. powershell) just set the corresponding keys in the registry. I don't know exactly what else I could try.



I hope that somebody got the clue where to enable this.







windows-server-2012 tls exchange-2013






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Feb 16 '15 at 12:51









KevinKevin

3162510




3162510







  • 1





    Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

    – YuKYuK
    Feb 16 '15 at 12:59











  • I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

    – Kevin
    Feb 16 '15 at 13:14






  • 2





    KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

    – YuKYuK
    Feb 16 '15 at 13:20











  • Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

    – Kevin
    Feb 16 '15 at 13:25







  • 1





    Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

    – Kevin
    Feb 16 '15 at 13:34












  • 1





    Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

    – YuKYuK
    Feb 16 '15 at 12:59











  • I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

    – Kevin
    Feb 16 '15 at 13:14






  • 2





    KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

    – YuKYuK
    Feb 16 '15 at 13:20











  • Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

    – Kevin
    Feb 16 '15 at 13:25







  • 1





    Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

    – Kevin
    Feb 16 '15 at 13:34







1




1





Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

– YuKYuK
Feb 16 '15 at 12:59





Check for lastest windows update . Because microsoft failled an update with schannel (tls subsystem) and changed the order for cipher . There is a tool to check cipher order in gui : nartac.com/Products/IISCrypto for me he work everytime (try on test machine if you don't trust the exe) .

– YuKYuK
Feb 16 '15 at 12:59













I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

– Kevin
Feb 16 '15 at 13:14





I already tried that tool, and it tells me that TLS 1.2 is enabled. I also tried to disable it --> reboot and enable it again --> reboot. If this is important I might edit the question and post the order, just tell me. However do you know which Windows update in particular I should look for, as I can't just install all updates before the next maintainence window.

– Kevin
Feb 16 '15 at 13:14




2




2





KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

– YuKYuK
Feb 16 '15 at 13:20





KB2992611 is the one with fail cipher order (bug on a lot of client) . They updated it . For more details : support.microsoft.com/kb/2992611

– YuKYuK
Feb 16 '15 at 13:20













Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

– Kevin
Feb 16 '15 at 13:25






Thank you. This particular update is in fact missing on our server. I'll try that and report the result.

– Kevin
Feb 16 '15 at 13:25





1




1





Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

– Kevin
Feb 16 '15 at 13:34





Hello YuKYuK. The KB2992611 update solved my problem. The intersting fact although is that the other Exchange server also is missing that update. It works however.

– Kevin
Feb 16 '15 at 13:34










1 Answer
1






active

oldest

votes


















0














One other option to enable SSL/TLS on your Windows Server is to use SSL crypto to updates the registry keys.



Furthermore you have the possibility to manage the cipher suite (Ciphers, Hashes and Key Exchanges).



https://www.nartac.com/Products/IISCrypto






share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f668026%2fenable-tls-1-2-in-windows-server-2012-running-exchange-2013-via-iis-8-0%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    One other option to enable SSL/TLS on your Windows Server is to use SSL crypto to updates the registry keys.



    Furthermore you have the possibility to manage the cipher suite (Ciphers, Hashes and Key Exchanges).



    https://www.nartac.com/Products/IISCrypto






    share|improve this answer



























      0














      One other option to enable SSL/TLS on your Windows Server is to use SSL crypto to updates the registry keys.



      Furthermore you have the possibility to manage the cipher suite (Ciphers, Hashes and Key Exchanges).



      https://www.nartac.com/Products/IISCrypto






      share|improve this answer

























        0












        0








        0







        One other option to enable SSL/TLS on your Windows Server is to use SSL crypto to updates the registry keys.



        Furthermore you have the possibility to manage the cipher suite (Ciphers, Hashes and Key Exchanges).



        https://www.nartac.com/Products/IISCrypto






        share|improve this answer













        One other option to enable SSL/TLS on your Windows Server is to use SSL crypto to updates the registry keys.



        Furthermore you have the possibility to manage the cipher suite (Ciphers, Hashes and Key Exchanges).



        https://www.nartac.com/Products/IISCrypto







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Jul 21 '17 at 14:18









        Alexandre RouxAlexandre Roux

        320116




        320116



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f668026%2fenable-tls-1-2-in-windows-server-2012-running-exchange-2013-via-iis-8-0%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

            Bruxelas-Capital Índice Historia | Composición | Situación lingüística | Clima | Cidades irmandadas | Notas | Véxase tamén | Menú de navegacióneO uso das linguas en Bruxelas e a situación do neerlandés"Rexión de Bruxelas Capital"o orixinalSitio da rexiónPáxina de Bruselas no sitio da Oficina de Promoción Turística de Valonia e BruxelasMapa Interactivo da Rexión de Bruxelas-CapitaleeWorldCat332144929079854441105155190212ID28008674080552-90000 0001 0666 3698n94104302ID540940339365017018237

            What should I write in an apology letter, since I have decided not to join a company after accepting an offer letterShould I keep looking after accepting a job offer?What should I do when I've been verbally told I would get an offer letter, but still haven't gotten one after 4 weeks?Do I accept an offer from a company that I am not likely to join?New job hasn't confirmed starting date and I want to give current employer as much notice as possibleHow should I address my manager in my resignation letter?HR delayed background verification, now jobless as resignedNo email communication after accepting a formal written offer. How should I phrase the call?What should I do if after receiving a verbal offer letter I am informed that my written job offer is put on hold due to some internal issues?Should I inform the current employer that I am about to resign within 1-2 weeks since I have signed the offer letter and waiting for visa?What company will do, if I send their offer letter to another company