7.11 Ensure Triple DES Cipher Suite is configured

Information

Enabling Triple DES Cipher Suites may be required for client compatibility. Enable or disable this cipher suite accordingly.

Rationale:

This item is Not Scored for the following reasons:

Enabling AES 256/256 is recommended.

This cipher does not suffer from known practical attacks.

Solution

To enable Triple DES 168/168, ensure the following key is not present or is set to 0xFFFFFFFF.

HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168\Enabled

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 6e7c0de3dedded660c5f10263cfcff9cdb53dfa403bcd76e0bb6b8871790fb02