Enable TLS 1.2 Exchange 2010

exchangeexchange-2010windows-server-2012

Due to Microsoft's announcement that TLS 1.0 and 1.1 will be end of support, the company is now asking to get TLS 1.2 enabled and by default.

My question is, what are the complete steps on enabling TLS 1.2 on Exchange 2010? We are currently running on RU17. What do I need to do to enable it?

I don't see TLS 1.2 in the Windows registry.

Best Answer

First, Install SP3 RU19:

https://technet.microsoft.com/en-us/library/hh135098(v=exchg.150).aspx

Using IIS crypto is the easiest way to check and set all your SChannel settings at a glance:

https://www.nartac.com/Products/IISCrypto

NOTE: If you disable TLS 1.0 and below then all of your clients will need to be at the correct patch level to communicate with all Exchange subsystems. Specifically Windows 7 clients need a special process that I recently went through here: Outlook 2013: MailTips, OOF, Free/Busy Availability all failing to pull from Exchange 2010 server

Related Topic