It is recommended that you configure your Manager server to fix the following vulnerability issues:
Vulnerability message | Port | Configuration Changes |
|---|---|---|
X.509 Certificate Subject CN Does Not Match the Entity Name (certificate-common-name-mismatch) | NA | Replace self-signed SSL certificate with a CA-signed SSL certificate. |
SMB signing disabled (cifs-smb-signing-disabled) SMB signing not required (cifs-smb-signing-not-required) | NA | Configure SMB signing for Windows. SMB signing is enabled on the server side if the following conditions are true:
|
TLS/SSL Birthday attacks on 64-bit block ciphers (SWEET32) (ssl-cve-2016-2183-sweet32) | NA |
|
TLS/SSL Server Supports RC4 Cipher Algorithms (CVE-2013-2566) (rc4-cve-2013-2566) | NA |
|
TLS/SSL Server Supports The Use of Static Key Ciphers (ssl-static-key-ciphers) | NA |
|
TLS Server Supports TLS version 1.1 (tlsv1_1-enabled) | NA | Disable support for TLSv1.0 & TLSv1.1 |
Diffie-Hellman group smaller than 2048 bits (tls-dh-prime-under-2048-bits) | Na |
|
TLS/SSL Server Is Using Commonly Used Prime Numbers (tls-dh-primes) | NA | Disable support for TLSv1.0 & TLSv1.1 |
ICMP timestamp response (generic-icmp-timestamp) | 443 8501 8502 8503 8506 8507 8508 | Enable Windows firewall and disable the ICMP timestamp response. To do this, perform the following steps:
|
TLS/SSL Server Supports 3DES Cipher Suite (ssl-3des-ciphers) | NA |
|
SSL Certificate Signed Using Weak Hashing Algorithm | 3389 | Contact the Certificate Authority to issue a certificate signed with strong hashing algorithm. |
Note
The exact vulnerability message might differ based on the Vulnerability Scanner you use.
Most of the configuration changes require changes to the Windows registry and you should be careful when changing the registry values. For general information on changing the Windows registry values, see the Microsoft Knowledge Base article 310516.