Hi again,
First I'd like to say thanks to the support folks at eukhost. I have been working through the various issues that came out of my PCI scan. Some of them I could resolve myself, some I needed specific support help for. Support were very helpful and experienced, and applied updates quickly and without fuss. Thank you!
When I get through the full list of PCI issues I hope to add to this thread, or perhaps create a new one, detailing all the steps I had to take, for the benefit of others.
There are a couple of issues from the scan that I could use some guidance on - hence the public post.
Using SSL 2.0 has been highlighted as a potential security risk, in particular, it was in relation to port 8443 for the Plesk control panel. They recommend disabling SSL 2.0 and making sure the server just uses SSL 3.0 or TLS.
I have done some reading around this issue, and although this is simple on Linux servers, Windows servers seem to have more of a problem. I can see how to make a registry change to disable IIS from using SSL 2.0 But a lot of people are saying that Plesk doesn't function correctly, or doesn't function at all, without SSL 2.0 on Windows servers.
Has anyone else had to disable SSL 2.0 on a Windows server? And did Plesk work OK after you did this?
There was another security problem relating to security ciphers used by Plesk, but we can come back to that if there's a solution/workaround to the SSL 2.0 issue.
Many thanks in advance.
|