Allow Fallback to SSL 3.0 (Internet Explorer) must be disabled.
An XCCDF Rule
Description
This parameter ensures only DoD-approved ciphers and algorithms are enabled for use by the web browser by blocking an insecure fallback to SSL when TLS 1.0 or greater fails. Satisfies: SRG-APP-000514, SRG-APP-000555, SRG-APP-000625, SRG-APP-000630, SRG-APP-000635
- ID
- SV-250541r942485_rule
- Version
- DTBI1100-IE11
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Security Features >> "Allow fallback to SSL 3.0 (Internet Explorer)" to "Enabled", and select "No Sites" from the drop-down box.