Skip to main content

Nartac Software releases IIS Crypto 3.3 on October 31, 2022. This IIS Crypto update adds TLS 1.3 for Windows Server 2022, new cipher suites, updated templates, including PCI 4.0 changes, and some minor fixes.

IIS Crypto

IIS Crypto is a free tool that gives administrators the ability to enable or disable protocols, ciphers, hashes and key exchange algorithms on Windows Server 2008, 2012, 2016, 2019 and 2022. It also lets you reorder SSL/TLS cipher suites offered by IIS, change advanced settings, implement Best Practices with a single click, create custom templates and test your website.

IIS Crypto updates the registry using the same settings from this article by Microsoft. It also updates the cipher suite order in the same way that the Group Policy Editor (gpedit.msc) does. Additionally IIS Crypto lets you create custom templates that can be saved for use on multiple servers. The command line version contains the same built-in templates as the GUI version and can also be used with your own custom templates.

You can download IIS Crypto in both GUI and command line versions.

IIS Crypto 3.3 download

IIS Crypto support

IIS Crypto has been tested on the below Windows Server versions:

  • Windows Server 2008/2008 R2
  • Windows Server 2012/2012 R2
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022

IIS Crypto features

IIS Crypto has a lot of excellent features:

  • Single click to secure your website using Best Practices
  • Backup the registry before making any updates
  • Change advanced registry settings
  • Built in Best Practices, PCI 4.0, Strict and FIPS 140-2 templates
  • Create custom templates that can be saved and run on multiple servers
  • Revert back to the original server’s default settings
  • Stop DROWN, logjam, FREAK, POODLE and BEAST attacks
  • Enable TLS 1.1, 1.2 and 1.3*
  • Enable forward secrecy
  • Reorder cipher suites
  • Disable weak protocols and ciphers such as SSL 2.0, 3.0, MD5 and 3DES
  • Site Scanner to test your configuration
  • Command line version

*Requires Windows Server 2022 or newer.

IIS Crypto 3.3

IIS Crypto 3.3

IIS Crypto 3.3 build 17 (October 31, 2022) changelog:

  • Added TLS 1.3 and new cipher suites for Windows Server 2022
  • Updated all templates to support TLS 1.3
  • PCI 4.0 template added which removes SHA1 and non forward secrecy cipher suites
  • Strict template removes CBC cipher suites on Windows 2016 and above
  • Removed a single instance check on startup

Leave a Reply