IISW-SV-000137 - The production IIS 8.5 web server must utilize SHA2 encryption for the Machine Key - Validation Method

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Machine Key element of the ASP.NET web.config specifies the algorithm and keys that ASP.NET will use for encryption. The Machine Key feature can be managed to specify hashing and encryption settings for application services such as view state, forms authentication, membership and roles, and anonymous identification. Ensuring a strong encryption method can mitigate the risk of data tampering in crucial functional areas such as forms authentication cookies, or view state.

Solution

If .NET is not installed, this is Not Applicable.

Open the IIS 8.5 Manager.

Click the IIS 8.5 web server name.

Double-click the 'Machine Key' icon in the web server Home Pane.

Set the Validation method to 'HMACSHA256' or stronger.
Set the Encryption method to 'Auto'.

Click 'Apply' in the 'Actions' pane.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_8-5_Y22M01_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001199, Rule-ID|SV-214422r508658_rule, STIG-ID|IISW-SV-000137, STIG-Legacy|SV-91427, STIG-Legacy|V-76731, Vuln-ID|V-214422

Plugin: Windows

Control ID: 741d7f167291e19961677b32fd32e22978d84534cf1a8f507422833dd567bf7d