Disabling SSLv2 for PCI-DSS Scan

Are you running a Small Business Server (SBS) or a Windows Home Server (WHS)? If so, chances are you have forwarded port 443 (SSL) on your router or firewall to point to your server in order to utilize the Remote Web Workplace (Access) feature of these servers. The Payment Card Industry (PCI) requires certain standards to be in place if you are processing credit card information. One of those standards is that SSLv2 is deemed unacceptable, and you will fail a PCI scan if its enabled.

Disabling SSLv2 requires a simple registry edit. I have tested this with both SBS and WHS. Copy and paste the following lines into a empty text file, and aftersaving it, rename the text file to use a .reg suffix (e.g. disable-sslv2.reg).

Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server]
“Enabled”=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server]
“Enabled”=dword:00000000

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.