screenshot of ssllabs.com results

How to disable SSLv3 and RC4 ciphers in IIS

Sam Rueby Security, Web Development 5 Comments

There’s a great tool from Qualys SSL Labs¬†that will test your server’s configuration for the HTTPS protocol. Somewhat-unfortunately, servers default configuration tends to favor compatibility over security. If you want to get your grade up to an A- or better you will have to make some configuration changes. Here’s what I did while using Windows Server 2008 R2 and IIS. …