SV-218807r561041_rule
V-218807
SRG-APP-000231-WSR-000144
IIST-SV-000137
CAT II
10
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Machine Key" icon in the web server Home Pane.
Set the Validation method to "HMACSHA256" or stronger.
Set the Encryption method to "Auto".
Click "Apply" in the "Actions" pane.
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Machine Key" icon in the website Home Pane.
Verify "HMACSHA256" or stronger encryption is selected for the Validation method and "Auto" is selected for the Encryption method.
If "HMACSHA256" or stronger encryption is not selected for the Validation method and/or "Auto" is not selected for the Encryption method, this is a finding.
If .NET is not installed, this is Not Applicable.
V-218807
False
IIST-SV-000137
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Machine Key" icon in the website Home Pane.
Verify "HMACSHA256" or stronger encryption is selected for the Validation method and "Auto" is selected for the Encryption method.
If "HMACSHA256" or stronger encryption is not selected for the Validation method and/or "Auto" is not selected for the Encryption method, this is a finding.
If .NET is not installed, this is Not Applicable.
M
4052