TLS 1.2 enabled by default ?

Uchil, Deepika 21 Reputation points
2021-01-11T06:45:00.76+00:00

I could not find any documentation which mentions all the windows clients/server which have TLS 1.2 enabled by default.

And if it says TLS 1.2 is enabled by default (for example in windows10), does it mean even though we don't have a registry entry in 'SCHANNEL' it is enabled ?

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2021-01-11T08:13:27.38+00:00

    Hi,

    According to below two articles, TLS 1.2 is enabled by default on Windows 8/Windows Server 2012 and later vsesions.
    "For TLS 1.2 default settings, see Protocols in the TLS/SSL (Schannel SSP)." While Protocols in the TLS/SSL (Schannel SSP) indicates TLS 1.2 is enabled.
    https://learn.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings#tls-12
    https://learn.microsoft.com/en-us/windows/win32/secauthn/protocols-in-tls-ssl--schannel-ssp-

    does it mean even though we don't have a registry entry in 'SCHANNEL' it is enabled?

    Below article mentioned "TLS 1.2 is enabled by default. Therefore, no change to these keys is needed to enable it." So, I think the answer for your question should be "Yes".
    https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/security/enable-tls-1-2-client#bkmk_protocol

    Hope the information helps.

    Thanks,
    Eleven


    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.