tls 1.2
2 TopicsTLS 1.2 & Server 2019
Trying to get through some prerequisites for an application and it asks about TLS 1.2. We are running Server 2019 and from all that I've Googled, it says that TLS 1.2 is enabled by default in Server 2019. But, when I look for the registry keys that are posted everywhere to verify TLS 1.2 is enabled, I don't see those keys. Also, when I run IIS Crypto from Nartac on the server in question, everything is greyed out, not showing as being enabled. What is the correct answer here?? Do I need to add those registry keys for TLS 1.2 to be enabled, or is it enabled by default? Very confused.Solved48KViews0likes4CommentsServer 2019 no "Server Hello" when using TLS_RSA_WITH_AES_ ciphers (TLS1.2) schannel 36874
Hi Hoping someone might have come across something similar as the support forum entries are filled with irrelevant responses and tumbleweed. A recently migrated CA cluster is not sending any TLS conversation completion when the client uses a cipher from the TLS_RSA_WITH_AES_* type (so TLS_RSA_WITH_AES_128_CBC_SHA256 or similar). This also seems to be negatively impacting RPC certificate enrolment from Windows 7 systems. Using Nartac tools and manually (double, triple, quadruple) checking the registry settings myself I can see that the ciphers are present in the list of supported/available ciphers. I can see that TLS1.2 is working. As soon as a client offers TLS_ECDH_* the server responds like an enthusiastic puppy. using TLS_RSA_WITH_AES_ it ignores the traffic (no server hello or attempt to negotiate) and logs Schannel Errors 36874 in the server event log. I have verified this using wireshark on client and server. Whilst these are hosted in azure there shouldn't be any network layer kit interfering with the connection. There is a standard load balancer which single routes all traffic to the active AD CS cluster node. No inspection or TLS termination should be occurring. There are no GPOs controlling anything to do with TLS or communication security (checked with gpresult and gpmc, along with repeated verification of the registry settings) has anyone seen anything like this before? yes I have been through the enabling TLS 1.2 articles a bajillion times and know where to enable TLS 1.2 for both schannel and .net In need of more straws to clutch at.1.3KViews0likes0Comments