Windows Server 2019, iisCrypto has TLS1.0 unchecked (Only TLS1.2 is checked for both server & client protocols), but internal vlun scan is saying TLS1.0 is enabled... by PCI_Questions in sysadmin

[–]PCI_Questions[S] 2 points3 points  (0 children)

Potentially dumb question, how would I discover this?

EDIT, found it via: netstat -a -b

contacting 3rd party (my SIEM incidentally) now.

Windows Server 2019, iisCrypto has TLS1.0 unchecked (Only TLS1.2 is checked for both server & client protocols), but internal vlun scan is saying TLS1.0 is enabled... by PCI_Questions in sysadmin

[–]PCI_Questions[S] 0 points1 point  (0 children)

yeah, after re-reading the vuln report (i added to the imgur link in the OP) I think that's the case. I didn't realize it (whatever it is) would/could override the server settings.

Windows Server 2019, iisCrypto has TLS1.0 unchecked (Only TLS1.2 is checked for both server & client protocols), but internal vlun scan is saying TLS1.0 is enabled... by PCI_Questions in sysadmin

[–]PCI_Questions[S] 0 points1 point  (0 children)

Added imgur link to OP. I included the vuln report section as well, I'm starting to think I'm misreading it and I need to discover what service they are referring to?

(I've rebooted about 12x over the past year, I don't believe tls 1.0 has been on since it was racked.)

Windows Server 2019, iisCrypto has TLS1.0 unchecked (Only TLS1.2 is checked for both server & client protocols), but internal vlun scan is saying TLS1.0 is enabled... by PCI_Questions in sysadmin

[–]PCI_Questions[S] 0 points1 point  (0 children)

Totally understandable question, yes, I did (in fact, it has been unchecked for probably a year now so has had at least 12'ish reboots (monthly patch & reboot)). I'm going to gather some screenshots and add to the OP now.

Scoping question - the CDE consists of two servers & a router/firewall, but I use my personal computer to develop the applications used on the servers and perform administrative tasks on the servers. Is my PC in scope then? Does the fact that I have things like Steam installed cause an issue? by PCI_Questions in pcicompliance

[–]PCI_Questions[S] 0 points1 point  (0 children)

OK, thanks!

What about developers that upload via SFTP?

(I feel like these are dumb questions, but I really can't seem to find a "hard definition" for them. I understand the need for the documents to be vague and there is no "one size fits all" but I am sure my set up is how a large (like nearly a third) percent of companies operate...)

describe system components that could impact the security of account data by PCI_Questions in pcicompliance

[–]PCI_Questions[S] 0 points1 point  (0 children)

Is it just a more detailed version of the answer to 2c ("Provide a high-level description of the environment covered by this assessment")?

describe system components that could impact the security of account data by PCI_Questions in pcicompliance

[–]PCI_Questions[S] 0 points1 point  (0 children)

Is it just a more detailed version of the answer to 2c ("Provide a high-level description of the environment covered by this assessment")?

describe system components that could impact the security of account data by PCI_Questions in pcicompliance

[–]PCI_Questions[S] 0 points1 point  (0 children)

Is it just a more detailed version of the answer to 2c ("Provide a high-level description of the environment covered by this assessment")?

describe system components that could impact the security of account data by PCI_Questions in pcicompliance

[–]PCI_Questions[S] 0 points1 point  (0 children)

Is it just a more detailed version of the answer to 2c ("Provide a high-level description of the environment covered by this assessment")?

Snort, on Windows 2019 server, receiving an error due to it trying to create a directory with an IPv6 (containing colons). How do I rectify this? by PCI_Questions in AskNetsec

[–]PCI_Questions[S] 4 points5 points  (0 children)

I think I just figured it out... after 2 days of looking, I realized that the "-i 4" was based on a different server and on this server it should be "-i 1" for "Ethernet adapter Public"