Step 2: To disable weak ciphers (including EXPORT ciphers) in Windows Server 2003 SP2, follow these steps.
ImportantThis section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
To edit these registry values, follow these steps:
- Click Start, click Run, type regedit in the Open box, and then click OK.
- Locate and then click the following subkey in the registry:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\
- On the Edit menu, point to New, and then click Key. Type the name of the key according to the following cipher names:DES 56/56
- On the Edit menu, point to New, and then click DWORD Value.
- Type Enabled for the name of the DWORD, and then press ENTER.
- Right-click Enabled, and then click Modify.
- In the Value data box, type 00000000, and then click OK.
- On the File menu, click Exit to quit Registry Editor.
In order of preference, the cipher suites that are available after you successfully follow these steps are as follows: