Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I have a suspicion there is no built-in GPO setting to do this.

 

The registry key involved is a HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings, valuename SecureProtocols. It's a DWORD bitflag that enables or disables all the various protcols that can be set using the Internet Control Panel. The flag for SSL2 is on bit 4.

 

Basically, find out what the current value is, and add 8 to the value, e.g. if the current value is 0x000000a0 (which I think it will be given what you've said), change it to 0x000000a8. How you deploy that registry value is up to you; personally I would use Group Policy Preferences.

  • Thanks 1
Posted

Turns out this wasn't the setting causing me gripe, but I created a custom ADM for this anyway. I've attached it in case anyone needs to roll this preference out (NOTE: Not a policy!).

 

It gives a drop-down with all the possible settings (TLS, SSL2, SSL2, TLS & SLL2 etc etc). Disabling it should return the setting to default. If you import this into your policy, you may not see it until you right-click Administrative Templates under User Configuration, then select View and Filtering and unchecking the Only show policy settings that can be fully managed. Once you do this you will find the setting in User Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Advanced Settings.

 

Hope somebody finds this useful. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...