Jump to content

using TLS v1.2 strict on KSC server


Go to solution Solved by MilanBortel,

Recommended Posts

Hello guys,
I want to use TLS v1.2 only on server with KSC. 

  1. changed settings according to https://help.kaspersky.com/KSC/11/en-US/174316.htm
  2. restarted KSC service, everything is working fine
  3. when I set up the windows server to use only TLS v1.2 https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings
  4. then MMC console won’t connect to KSC server, restarting KSC service doesn’t help, restarting windows server doesn’t help:
    KSC fails to connect

     

  5. only allowing TLS v1.0 from step 3 helps to recover the KSC

KSC is running on Windows Server 2016 Standard
SQL is running on Windows Server 2012 R2
SQL 2016
 

Thanks for your ideas,
Milan

Link to comment
Share on other sites

when you restart the ksc service, it takes a while (a few minutes) in order to be able to connect to it again. Maybe the service was not started yet?

I have not tried to change that setting, I cannot tell you if this works.

Link to comment
Share on other sites

when you restart the ksc service, it takes a while (a few minutes) in order to be able to connect to it again. Maybe the service was not started yet?

I have not tried to change that setting, I cannot tell you if this works.

I waited… and waited … and waited … trust me, that didn’t help 😥

Link to comment
Share on other sites

MSSQL communication can also be encrypted with SSL/TLS…

Or you have a database problem (is it running?).

  • with “MSSQL communication can also be encrypted with SSL/TLS” you mean exactly what? I found this article and the way I see it - SQL 2016 supports TLS v1.2, you don’t need to explicitly set this up
  • SQL is running, no problems at all..
Link to comment
Share on other sites

  • 4 weeks later...
  • 6 months later...
  • 2 years later...
On 5/25/2020 at 3:30 PM, MilanBortel said:

Let me close this topic - see attached instructions which helped to solve the situation.

 

Now, we are TLS 1.2 strict.

 

Cheers,
Milan

Hello

What were the attached insturctions ?

I've got the same issue whereby enabling TLS 1.2 on KSC but disabling 1.0 & 1.1 in the registry causes connectivity errors to KSC.

Thanks.

Edited by swoopy
Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...