SV-220805r569187_rule
V-220805
SRG-OS-000120-GPOS-00061
WN10-CC-000052
CAT II
10
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> SSL Configuration Settings >> "ECC Curve Order" to "Enabled" with "ECC Curve Order:" including the following in the order listed:
NistP384
NistP256
If the following registry value does not exist or is not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002\
Value Name: EccCurves
Value Type: REG_MULTI_SZ
Value: NistP384 NistP256
V-220805
False
WN10-CC-000052
If the following registry value does not exist or is not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002\
Value Name: EccCurves
Value Type: REG_MULTI_SZ
Value: NistP384 NistP256
M
4072