PCI Compliance and IIS 7
by Brian on Jan.14, 2010, under Windows Info
Need to determine if you are using weak ciphers in IIS?
Try SSLDigger, it’s a free utility from Foundstone.
Also, if you’re running Windows Server 2008, and want to just disable all weak ciphers, you can use these registry merge files.
Just merge them with your registry, and reboot. Here they are.
I should point out that just randomly merging registry files you've found on the Internet is a lot like eating a sandwich that you've found on the sidewalk. If you don't understand what you are doing, you may want to do a little research first. I can't help you if you destroy your servers with these files. You've been warned.
April 15th, 2010 on 9:58 pm
Much quicker than OpenSSL. Had to do this drill several times. Nice find.