SharePoint 2019 STIG Compliance DES RC4 MD5

Art 71 Reputation points
2020-08-14T17:32:49.057+00:00

I am trying to be compliant and I am stuck on the below request,

"Under “Options”, in the “SSL Cipher Suites” text box, enter desired cipher suites that are not DES or RC4."

If I remove RC4 that MD5 is in someway attached to, the "Central Administration" web page errors with a FIPS error.
I am sure the same will be said for the Web Application / Sites also.

I know that MD5 is required by SharePoint although that answer is not good enough to close this findings (V-59965, V-59967, V-59969, V-59971, V-59989).

I wish I could say that I have the understanding to present a technical reason why although I am at a loss and am asking for help.

I am also open to a possible book that discusses SharePoint and MD5, I believe what I have read that Microsoft uses FISMA instead of FIPS

SharePoint Server Management
SharePoint Server Management
SharePoint Server: A family of Microsoft on-premises document management and storage systems.Management: The act or process of organizing, handling, directing or controlling something.
2,818 questions
0 comments No comments
{count} votes

Accepted answer
  1. Trevor Seward 11,691 Reputation points
    2020-08-14T17:41:22.003+00:00

0 additional answers

Sort by: Most helpful