Configuring Servers to Support TLS 1.x with EmpowerID
In order to use Transport Layer Security (TLS) with EmpowerID, you must apply Microsoft patches to the SQL server and client machines, and add registry settings to the EmpowerID server and client machines.
Prerequisites
The .NET Framework version 4.5 or higher must be installed on the EmpowerID server.
To configure the EmpowerID server machine
From the Start menu, open the Registry Editor (regedit).
Expand the Computer node and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319
Right-click the v4.0.30317 key and select New, then DWORD (32-bit) Value.
Set the Name to SchUseStrongCrypto and the Value data to 1.
Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319
Again, right-click the v4.0.30317 key and select New, then DWORD (32-bit) Value, and add the same subkey:Â
Value name:Â SchUseStrongCrypto
Value data: 1
To configure the SQL Server machine
See the following information from Microsoft:
https://support.microsoft.com/en-us/help/3135244/tls-1.2-support-for-microsoft-sql-serverFrom that page, download and install the appropriate patch for your SQL Server version.
To update protocols on the EmpowerID server machine
This step disables insecure protocols on the EmpowerID server.
If you perform this step before installing the SQL patch, the EmpowerID server machine will no longer be able to communicate with the SQL Server.
Download and run the GUI version of IIS Crypto 2.0:
https://www.nartac.com/Products/IISCrypto/DownloadOn the Schannel tab that appears by default, under Protocols, clear all checkboxes except for TLS 1.1 and TLS 1.2 so that it looks like this:
Click Apply and restart the EmpowerID server.
To configure the client machine
On the client machine, download and install the appropriate patch for the Windows 7 or 2012 R2 machine:
https://support.microsoft.com/en-us/help/3080079/update-to-add-rds-support-for-tls-1.1-and-tls-1.2-in-windows-7-or-windows-server-2008-r2From the Start menu, open the Registry Editor (regedit).
Expand the Computer node and navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client
Right-click Client, select New, then DWORD (32-bit) Value, and set the Value name to DisabledByDefault. (Leave the Value data to the default value of 0.)
Repeat for each of the following keys: