mitre / microsoft-iis-8.5-server-stig-baseline

InSpec profile to validate an MS IIS Server to the DISA STIG

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

V-76759 doesn't need to check against all TLS & SSL versions

HackerShark opened this issue · comments

Currently the control checks every single version of TLS and SSL in the registry. This can be enhanced by checking if the registry entry exists first before running the control. This eliminates unnecessary control failures.

Pull request #28 created for this fix.

Rony's review makes it seem that all registry entries are required: #28 (comment)

Please reopen if this is not the case @HackerShark