Page view counter

IIS 6 and Require 128-bit Encryption for SSL and PCI requirements

Last post 07-15-2008 2:00 PM by kahanu. 2 replies.

Sort Posts:

  • IIS 6 and Require 128-bit Encryption for SSL and PCI requirements

    07-14-2008, 11:01 PM
    • Loading...
    • kahanu
    • Joined on 09-06-2007, 7:04 PM
    • Posts 88

    I'm trying to build a site that has a section that does NOT require an SSL certificate and another section that does. 

    For my Secure section I created a new virtual directory in IIS.  This section will has the SSL certificate.  Everything works as it should, except for the following issue.

    Here's my problem, my site just became non-PCI compliant because of a new vulnerability (that wasn't there months ago when I was PCI compliant).  The fix tells me to go into IIS and select the web site, folder or files that will be secure and go to Properties and Directory Security.  Then I'm supposed to check the box that says "Require 128-bit Encryption".  When I do that and run my site, I get an error that says the page must use https.

    I had my ASP.NET application handle making the URL https, but this IIS configuration breaks that.

    Does anyone know how to make this work?

    Let me know if you need more information.

    Thanks.

  • Re: IIS 6 and Require 128-bit Encryption for SSL and PCI requirements

    07-15-2008, 8:34 AM

    Try www.iis.net.

    Jeff

    Please: Don't forget to click "Mark as Answer" on the post that helped you. That way future readers will know which post solved your issue.
  • Re: IIS 6 and Require 128-bit Encryption for SSL and PCI requirements

    07-15-2008, 2:00 PM
    • Loading...
    • kahanu
    • Joined on 09-06-2007, 7:04 PM
    • Posts 88

    jeff@zina.com:

    Try www.iis.net.

    Jeff

     

    Jeff, thanks for the suggestion.  I posted a message there.  I hope I get an answer.  I'm surprised no one here has run into this.

Page 1 of 1 (3 items)
Microsoft Communities