Windows – SSL 3 is still enabled after setting registry keys and rebooting Windows 2008 R2

iis-7.5ssltlswindowswindows-server-2008-r2

I have searched all over and can't seem to find an answer.

I am attempting to disable SSL 3.0 and enable TLS 1.1 and TLS 1.2 on my Windows 2008 R2 server using IIS 7.5.

I have made all the registry changes necessary and have rebooted the server multiple times, but ssllabs.com is still reporting SSL3 on with TLS1.1 and TLS1.2 off.

I also used IISCrypto to apply the keys with the same results after reboot.

I have done this on all our other servers with success, but this server will not take the changes.

Any ideas?

Thanks,
James O.

Best Answer

Is your site behind a load balancer such that the public facing URL isn't directly going to your IIS box(es)? If so, you need to make those changes on the load balancer.