V-218807
CAT IIThe production IIS 10.0 web server must utilize SHA2 encryption for the Machine Key.
- Ships Affected
- 2
- Total Findings
- 3
- Open
- 0
- Closed
- 1
Check Text
Note: If ASP.NET is not installed, this is Not Applicable.
Note: If the IIS 10.0 web server is hosting Exchange, this is Not Applicable.
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Machine Key" icon in the website Home Pane.
Verify "HMACSHA256" or stronger encryption is selected for the Validation method and "Auto" is selected for the Encryption method.
If "HMACSHA256" or stronger encryption is not selected for the Validation method and/or "Auto" is not selected for the Encryption method, this is a finding.
If .NET is not installed, this is Not Applicable.
Fix Text
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Machine Key" icon in the web server Home Pane.
Set the Validation method to "HMACSHA256" or stronger.
Set the Encryption method to "Auto".
Click "Apply" in the "Actions" pane.
STIG Reference
- STIG
- Microsoft IIS 10.0 Server Security Technical Implementation Guide
- Version
- 3
- Release
- 7
- Rule ID
- SV-218807r1067586_rule
All Occurrences
This vulnerability appears on 2 ship(s)
| Ship | Hull # | Source File | Status | Assigned To | Scan Date | Actions |
|---|---|---|---|---|---|---|
| LAB BASELINES | BASELINE | SCHR-P3-DP-001_IIS10Server_V3R6_20260305-132942.cklb | Unassigned | 2026-03-12T15:38:14.420977 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_IIS10Server_V3R4_20251023-143809.ckl | Unassigned | 2026-01-14T12:57:35.201603 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Server_V3R4_20251023-152431.ckl | Unassigned | 2026-01-14T12:57:32.874734 | View in Context |