7.12 Ensure AES 128/128 Cipher Suite is configured

Information

Enabling AES 128/128 may be required for client compatibility. Enable or disable this cipher suite accordingly.

Rationale:

This item is Not Scored for the following reasons:

Enabling AES 256/256 is recommended.

This cipher does not suffer from known practical attacks.

Solution

To enable the AES 128/128 cipher, ensure the following key is set to 0xFFFFFFFF:

HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\AES 128/128\Enabled

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 4e3bf65239548460be262e1836de48a9264134449ff82e7d2346655e4f511bf2