[{"data":1,"prerenderedAt":349},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Frenforcer-securite-serveur-web-iis":3,"blog-\u002Fen\u002Fblog\u002Frenforcer-securite-serveur-web-iis-surround":288,"blog-\u002Fen\u002Fblog\u002Frenforcer-securite-serveur-web-iis-certifications":348},{"id":4,"title":5,"body":6,"categories":274,"cover":276,"cover_contain":277,"credly_badge_id":278,"date":279,"description":280,"extension":281,"meta":282,"navigation":277,"path":283,"related_certifications":278,"seo":284,"slug":285,"stem":286,"__hash__":287},"blog\u002Fen\u002Fblog\u002Frenforcer-securite-serveur-web-iis.md","Strengthening the Security of an IIS 8.5 Web Server",{"type":7,"value":8,"toc":259},"minimark",[9,14,18,22,25,28,83,87,92,121,125,133,136,139,146,153,158,161,165,172,177,186,190,197,202,205,209,215,220,224,241,250,255],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You're exposing an IIS web server on the Internet: here's how to strengthen its security, version 8.5.",[10,19,21],{"id":20},"the-security-of-a-web-server","The security of a web server",[15,23,24],{},"The security of a web server is often overlooked. Here are some of my IIS hardening methods, for a web server running version 8.5 on Windows Server 2012 R2 Standard.",[15,26,27],{},"To start, you need to understand the SSL\u002FTLS protocol and how it works. Personally, here are the tools\u002Fmethods I use to strengthen a web server:",[29,30,31,47,59,65,71,77],"ul",{},[32,33,34,38,39,46],"li",{},[35,36,37],"strong",{},"Signed certificate",": I've only used the ",[40,41,45],"a",{"href":42,"rel":43},"https:\u002F\u002Fletsencrypt.org\u002F",[44],"nofollow","Let's Encrypt"," authority since 2015, with a 3076-bit RSA key (2048-bit is still tolerated until 2030).",[32,48,49,52,53,58],{},[35,50,51],{},"Elliptic-curve Diffie-Hellman key exchange",": ",[40,54,57],{"href":55,"rel":56},"https:\u002F\u002Ffr.wikipedia.org\u002Fwiki\u002F%C3%89change_de_cl%C3%A9s_Diffie-Hellman_bas%C3%A9_sur_les_courbes_elliptiques",[44],"ECDHE"," key exchanges should be favored with the following curves: secp256r1, secp384r1, secp521r1, brainpoolP256r1, brainpoolP384r1, or brainpoolP512r1.",[32,60,61,64],{},[35,62,63],{},"Header restriction:"," limit REST information disclosure.",[32,66,67,70],{},[35,68,69],{},"Request logging:"," for tracking in case of an incident.",[32,72,73,76],{},[35,74,75],{},"IP address and domain restrictions \u002F Dynamic restrictions"," (anti-DoS).",[32,78,79,82],{},[35,80,81],{},"Endpoint Detection and Response"," (on the Windows server).",[10,84,86],{"id":85},"hardening-an-iis-85-web-server","Hardening an IIS 8.5 web server",[88,89,91],"h3",{"id":90},"signed-certificate-lets-encrypt-on-windows","Signed certificate: Let's Encrypt on Windows",[93,94,95,105,108,115,118],"ol",{},[32,96,97,98],{},"Download the latest available version of win-acme on your server: ",[40,99,102],{"href":100,"rel":101},"https:\u002F\u002Fgithub.com\u002FPKISharp\u002Fwin-acme\u002Freleases",[44],[35,103,104],{},"link",[32,106,107],{},"Unzip the archive on the server",[32,109,110,111,114],{},"Run ",[35,112,113],{},"wacs.exe",", then: \"N\", then \"1\", and choose your IIS site (domain validation via port 80).",[32,116,117],{},"Your website is then certified by a valid authority.",[32,119,120],{},"Check the IIS bindings and the certificates used.",[88,122,124],{"id":123},"protocols-ciphers-hashes-and-key-exchange","Protocols, ciphers, hashes, and key exchange",[15,126,127,128],{},"Download: ",[40,129,132],{"href":130,"rel":131},"https:\u002F\u002Fwww.nartac.com\u002FProducts\u002FIISCrypto\u002FDownload",[44],"IIS Crypto",[15,134,135],{},"Run the program.",[15,137,138],{},"Here's my configuration:",[15,140,141],{},[142,143],"img",{"alt":144,"src":145},"","\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F99c2d99525.png",[15,147,148,149,152],{},"In the ",[35,150,151],{},"Cipher Suites"," section, here are my preferences:",[15,154,155],{},[142,156],{"alt":144,"src":157},"\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F423abb8b1a.png",[15,159,160],{},"Confirm your choices and restart the Windows server.",[88,162,164],{"id":163},"limiting-fingerprinting","Limiting fingerprinting",[15,166,167,168,171],{},"In the IIS server, go to: ",[35,169,170],{},"HTTP Response Headers"," (here's my configuration):",[15,173,174],{},[142,175],{"alt":144,"src":176},"\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F0278078f7f.png",[15,178,179,180,185],{},"I strongly encourage you to research each directive (e.g., ",[40,181,184],{"href":182,"rel":183},"https:\u002F\u002Fdeveloper.mozilla.org\u002Ffr\u002Fdocs\u002FWeb\u002FHTTP\u002FCSP",[44],"Content-Security-Policy",").",[88,187,189],{"id":188},"more-verbose-logs","More verbose logs",[15,191,192,193,196],{},"To get more information about the requests received by your sites, go to the ",[35,194,195],{},"Logging"," tab:",[15,198,199],{},[142,200],{"alt":144,"src":201},"\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F4091257ca3.png",[15,203,204],{},"The logs are more verbose and useful in the event of a server issue.",[88,206,208],{"id":207},"ip-address-and-domain-restrictions","IP address and domain restrictions",[15,210,148,211,214],{},[35,212,213],{},"IP Address and Domain Restrictions"," tab, I mainly use dynamic restriction:",[15,216,217],{},[142,218],{"alt":144,"src":219},"\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F606c412aff.png",[88,221,223],{"id":222},"endpoint-detection-and-response-optional","Endpoint Detection and Response (optional)",[15,225,226,227,232,233,240],{},"Unusual behavior on a web server is often a sign of attack attempts. EDR lets you monitor the machine's behavior. I ",[40,228,231],{"href":229,"rel":230},"https:\u002F\u002Fwww.bitdefender.com\u002Fbusiness\u002Fenterprise-products\u002Fultra-security.html",[44],"currently use the Bitdefender"," EDR solution. For more information: external ",[40,234,237],{"href":235,"rel":236},"https:\u002F\u002Fblog.varonis.fr\u002Fendpoint-detection-and-response-edr\u002F",[44],[35,238,239],{},"EDR article",".",[15,242,243,244,249],{},"Once your IIS web server is hardened, you should get the following result on ",[40,245,248],{"href":246,"rel":247},"https:\u002F\u002Fwww.ssllabs.com\u002Fssltest\u002F",[44],"ssllabs.com",":",[15,251,252],{},[142,253],{"alt":144,"src":254},"\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002F2b68d83362.png",[10,256,258],{"id":257},"conclusion","Conclusion",{"title":144,"searchDepth":260,"depth":260,"links":261},2,[262,263,264,273],{"id":12,"depth":260,"text":13},{"id":20,"depth":260,"text":21},{"id":85,"depth":260,"text":86,"children":265},[266,268,269,270,271,272],{"id":90,"depth":267,"text":91},3,{"id":123,"depth":267,"text":124},{"id":163,"depth":267,"text":164},{"id":188,"depth":267,"text":189},{"id":207,"depth":267,"text":208},{"id":222,"depth":267,"text":223},{"id":257,"depth":260,"text":258},[275],"Microsoft","\u002Fimages\u002Fblog\u002Frenforcer-securite-serveur-web-iis\u002Ffb6dc34cb9.png",true,null,"2019-05-27","Strengthening the security of an IIS 8.5 web server. Let's Encrypt Windows certificate, protocols, ciphers, hashes, and key exchange.","md",{},"\u002Fen\u002Fblog\u002Frenforcer-securite-serveur-web-iis",{"title":5,"description":280},"renforcer-securite-serveur-web-iis","en\u002Fblog\u002Frenforcer-securite-serveur-web-iis","f0OxOijVXTw5cCPUkKxzPniS7_-5n8rFLXI5naEWnlI",[289,297,304,312,319,327,334,341],{"title":290,"path":291,"stem":292,"date":293,"cover":294,"categories":295,"children":-1},"Vade Secure Sales","\u002Fen\u002Fblog\u002Fcertificat-commerciale-vade-secure","en\u002Fblog\u002Fcertificat-commerciale-vade-secure","2020-04-02","\u002Fimages\u002Fblog\u002Fcertificat-commerciale-vade-secure\u002F89e76075b0.png",[296],"Certifications",{"title":298,"path":299,"stem":300,"date":293,"cover":301,"categories":302,"children":-1},"Office 365 Administration Vade Level 1","\u002Fen\u002Fblog\u002Fcertificat-office-365-administration-vade-niveau","en\u002Fblog\u002Fcertificat-office-365-administration-vade-niveau","\u002Fimages\u002Fblog\u002Fcertificat-office-365-administration-vade-niveau\u002F89e76075b0.png",[296,303],"Sécurité",{"title":305,"path":306,"stem":307,"date":308,"cover":309,"categories":310,"children":-1},"IRF Configuration on Comware OS","\u002Fen\u002Fblog\u002Fconfiguration-irf-sous-comware","en\u002Fblog\u002Fconfiguration-irf-sous-comware","2019-07-24","\u002Fimages\u002Fblog\u002Fconfiguration-irf-sous-comware\u002F8ed76c4826.jpg",[311],"Réseau",{"title":313,"path":314,"stem":315,"date":316,"cover":317,"categories":318,"children":-1},"Installing and Configuring Azure Active Directory Connect","\u002Fen\u002Fblog\u002Finstallation-configuration-azure-active-directory-connect","en\u002Fblog\u002Finstallation-configuration-azure-active-directory-connect","2019-07-21","\u002Fimages\u002Fblog\u002Finstallation-configuration-azure-active-directory-connect\u002Fcdb7eff504.png",[275],{"title":320,"path":321,"stem":322,"date":323,"cover":324,"categories":325,"children":-1},"Hack In Paris, Cybersecurity Conference June 16-20, 2019","\u002Fen\u002Fblog\u002Fhack-paris-conference-cybersecurite-juin-2019","en\u002Fblog\u002Fhack-paris-conference-cybersecurite-juin-2019","2019-04-04","\u002Fimages\u002Fblog\u002Fhack-paris-conference-cybersecurite-juin-2019\u002F5161b6e99f.png",[326],"Évènement",{"title":328,"path":329,"stem":330,"date":331,"cover":332,"categories":333,"children":-1},"Discover the Cloud with Amazon Web Services","\u002Fen\u002Fblog\u002Fcertificat-decouvrez-cloud-avec-amazon-web-services","en\u002Fblog\u002Fcertificat-decouvrez-cloud-avec-amazon-web-services","2019-03-04","\u002Fimages\u002Fblog\u002Fcertificat-decouvrez-cloud-avec-amazon-web-services\u002Fd9bc5707d7.jpg",[296],{"title":335,"path":336,"stem":337,"date":338,"cover":339,"categories":340,"children":-1},"Installing and Configuring OpenSSH in PowerShell","\u002Fen\u002Fblog\u002Finstallation-configuration-openssh-powershell","en\u002Fblog\u002Finstallation-configuration-openssh-powershell","2019-01-06","\u002Fimages\u002Fblog\u002Finstallation-configuration-openssh-powershell\u002F126ef9a056.png",[275],{"title":342,"path":343,"stem":344,"date":345,"cover":346,"categories":347,"children":-1},"Conduct a Penetration Test","\u002Fen\u002Fblog\u002Fcertificat-conduisez-test-intrusion","en\u002Fblog\u002Fcertificat-conduisez-test-intrusion","2019-01-01","\u002Fimages\u002Fblog\u002Fcertificat-conduisez-test-intrusion\u002F0a074eac78.png",[303],[],1786644884761]