7.4 Ensure TLS 1.0 is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The PCI Data Security Standard 3.1 recommends disabling 'early TLS' along with SSL:

SSL and early TLS are not considered strong cryptography and cannot be used as a security control after June 30, 2016.

Solution

Review the following registry locations to verify that TLS 1.0 is configured as expected.
Disabled settings - Enabled to 0.
HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server\Enabled

See Also

https://workbench.cisecurity.org/files/166