SV-214422r508658_rule
V-214422
SRG-APP-000231-WSR-000144
IISW-SV-000137
CAT II
10
If .NET is not installed, this is Not Applicable.
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Double-click the "Machine Key" icon in the web server Home Pane.
Set the Validation method to "HMACSHA256" or stronger.
Set the Encryption method to "Auto".
Click "Apply" in the "Actions" pane.
If .NET is not installed, this is Not Applicable.
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Double-click the "Machine Key" icon in the website Home Pane.
Verify "HMACSHA256" or stronger encryption is selected for the Validation method and "Auto" is selected for the Encryption method.
If "HMACSHA256" or stronger encryption is not selected for the Validation method and/or "Auto" is not selected for the Encryption method, this is a finding.
V-214422
False
IISW-SV-000137
If .NET is not installed, this is Not Applicable.
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Double-click the "Machine Key" icon in the website Home Pane.
Verify "HMACSHA256" or stronger encryption is selected for the Validation method and "Auto" is selected for the Encryption method.
If "HMACSHA256" or stronger encryption is not selected for the Validation method and/or "Auto" is not selected for the Encryption method, this is a finding.
M
4000