{"id":929,"date":"2015-07-05T12:05:44","date_gmt":"2015-07-05T10:05:44","guid":{"rendered":"https:\/\/www.vioreliftode.com\/?p=929"},"modified":"2016-04-14T13:21:31","modified_gmt":"2016-04-14T11:21:31","slug":"test-your-ssl-settings-now-and-configure-your-internal-certification-authority-to-use-sha256","status":"publish","type":"post","link":"https:\/\/www.vioreliftode.com\/index.php\/test-your-ssl-settings-now-and-configure-your-internal-certification-authority-to-use-sha256\/","title":{"rendered":"Test your SSL settings now and configure your internal Certification Authority to use SHA256"},"content":{"rendered":"<input class=\"fooboxshare_post_id\" type=\"hidden\" value=\"929\"\/><p>This post is much more as an update for the &#8220;next-next-finish&#8221; approach of setting up a TLS\/SSL site, or Microsoft Internal Certificate Authority.<\/p>\n<p>&nbsp;<\/p>\n<p>It started months in the past and if you didn&#8217;t implement the fixes yet, at least is good to be aware of:<\/p>\n<ul>\n<li><a href=\"http:\/\/googleonlinesecurity.blogspot.de\/2014\/09\/gradually-sunsetting-sha-1.html\" target=\"_blank\">Gradually sunsetting SHA-1<\/a><\/li>\n<li><a href=\"https:\/\/community.qualys.com\/blogs\/securitylabs\/2014\/10\/15\/ssl-3-is-dead-killed-by-the-poodle-attack\" target=\"_blank\">SSL 3 is dead, killed by the POODLE attack<\/a><\/li>\n<li><a href=\"https:\/\/community.qualys.com\/blogs\/securitylabs\/2013\/03\/19\/rc4-in-tls-is-broken-now-what\" target=\"_blank\"><span style=\"line-height: 1.5;\">RC4 in TLS is Broken: Now What?<\/span><\/a><\/li>\n<li><span style=\"line-height: 1.5;\"><a href=\"https:\/\/www.perfectforwardsecrecy.com\/\" target=\"_blank\">Perfect Forward Secrecy<\/a> &amp; <a href=\"https:\/\/en.wikipedia.org\/wiki\/Forward_secrecy\" target=\"_blank\">Forward secrecy (Wikipedia)<\/a><\/span><\/li>\n<li><span style=\"line-height: 1.5;\">If you have a fresh new Windows Server 2012 R2 and you setup an internal Certificate Authority it will by default be configured to use SHA1! Don&#8217;t resume to\u00a0next-next-finish setup.<\/span><\/li>\n<li><span style=\"line-height: 1.5;\">If you already have an internal Certificate Authority, most likely is using SHA1. It is recommended to change it.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>1. <strong><span style=\"text-decoration: underline;\">If you have a TLS\/SSL web site<\/span><\/strong>, verify now your overall rating on <a href=\"https:\/\/www.ssllabs.com\/ssltest\/index.html\" target=\"_blank\">SSL LABS<\/a>.<br \/>\nIn case you are not rated to A, then the following article will for sure get you there &#8211; <a href=\"https:\/\/www.hass.de\/content\/setup-your-iis-ssl-perfect-forward-secrecy-and-tls-12\" target=\"_blank\">https:\/\/www.hass.de\/content\/setup-your-iis-ssl-perfect-forward-secrecy-and-tls-12<\/a> (the article is well written and the basic explanation is provided). Follow the article, or simply execute the PowerShell script.<\/p>\n<p>How vioreliftode.com is rated after the changes?<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_01.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-933\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_01.png\" alt=\"Test_Your_SSL_settings_01\" width=\"953\" height=\"623\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_01.png 953w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_01-300x196.png 300w\" sizes=\"(max-width: 953px) 100vw, 953px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>2. <span style=\"text-decoration: underline;\"><strong>If you have a fresh new Windows Server 2012 R2 and you setup an internal Certificate Authority<\/strong><\/span> make sure during the setup (in the Cryptography for CA section) you select SHA256 as hashing algorithm and minimum 2048 for the key length. As mentioned above, by default the wizard is configured to use <span style=\"text-decoration: underline;\">SHA1 -&gt; DON&#8217;T use it anymore!<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_02.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-934\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_02.png\" alt=\"Test_Your_SSL_settings_02\" width=\"776\" height=\"569\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_02.png 776w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/07\/Test_Your_SSL_settings_02-300x220.png 300w\" sizes=\"(max-width: 776px) 100vw, 776px\" \/><\/a><br \/>\n<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>3. <span style=\"text-decoration: underline;\"><strong>If you already have an internal Certificate Authority, most likely is using SHA1. It is recommended to change it.<\/strong><\/span> This is not difficult at all.<br \/>\n<a href=\"http:\/\/blogs.technet.com\/b\/pki\/archive\/2013\/09\/19\/upgrade-certification-authority-to-sha256.aspx\" target=\"_blank\">http:\/\/blogs.technet.com\/b\/pki\/archive\/2013\/09\/19\/upgrade-certification-authority-to-sha256.aspx<\/a><br \/>\n<a href=\"http:\/\/www.cusoon.fr\/update-microsoft-certificate-authorities-to-use-the-sha-2-hashing-algorithm-2\" target=\"_blank\">http:\/\/www.cusoon.fr\/update-microsoft-certificate-authorities-to-use-the-sha-2-hashing-algorithm-2<\/a><br \/>\n<a href=\"http:\/\/windowsitpro.com\/security\/your-organization-using-sha-1-ssl-certificates\" target=\"_blank\">http:\/\/windowsitpro.com\/security\/your-organization-using-sha-1-ssl-certificates<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>As an update to the above articles &#8211; it is not mandatory or critical to renew your Certification Authority Certificate Root. The CA root can still stay SHA1, what is important is the new certificates your CA is issuing to be SHA256.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This post is much more as an update for the &#8220;next-next-finish&#8221; approach of setting up a TLS\/SSL site, or Microsoft Internal Certificate Authority. &nbsp; It started months in the past and if you didn&#8217;t implement the fixes yet, at least is good to be aware of: Gradually sunsetting SHA-1 SSL 3 is dead, killed by &hellip; <a href=\"https:\/\/www.vioreliftode.com\/index.php\/test-your-ssl-settings-now-and-configure-your-internal-certification-authority-to-use-sha256\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Test your SSL settings now and configure your internal Certification Authority to use SHA256<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"Test your SSL settings now and configure your internal Certification Authority to use SHA256 https:\/\/wp.me\/p4NfDd-eZ","jetpack_is_tweetstorm":false},"categories":[32],"tags":[87,86,85,84,37],"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4NfDd-eZ","_links":{"self":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts\/929"}],"collection":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/comments?post=929"}],"version-history":[{"count":0,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts\/929\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/media?parent=929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/categories?post=929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/tags?post=929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}