How to change the SSL/TLS server configuration to only allow strong key exchanges with a strong Key size of 2048 bits

Meddeb, Mohamed 0 Reputation points
2025-02-11T07:33:48.7733333+00:00

How to change the SSL/TLS server configuration to only allow strong key exchanges with a strong Key size of 2048 bits on windows server 2016

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,575 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 29,376 Reputation points Microsoft Vendor
    2025-02-12T14:06:21.6+00:00

    Hello

    Thank you for posting in Q&A forum.

    It seems there is not a single system wide setting that allows you to adjust strong key exchanges settings for all applications, servers and services.

    You can try to change the SSL/TLS settings in applications or web browser or Windows machines.

    Here are two similar threads for your reference.

    https://serverfault.com/questions/1148774/how-to-disable-ssl-tls-diffie-hellman-keys-less-that-2048-bits

    https://community.cisco.com/t5/network-security/strong-key-exchange-for-vulnerability/td-p/4652329

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.