Basic Install settings for Windows Server to meet HSIT standards

Summary

This document will detail how set the HSIT settings for a new Server based upon our recommendations.

Body

Audience

Staff

 

Overview

This document will detail how set the HSIT settings for a new Server based upon our recommendations.

Basic Install settings for Windows Server to meet HSIT standards

Steps

The settings below are not required to do in any particular order.

  1. The first area to work in is the Server Management screen that opens automatically upon login.
    1. On the top right hand side click "Manage". This will display the sub-menu listing options. The last option is the "Server Manager Properties". Click the last option to display the "Server Manager Properties" page.
      1. The first check box is for the amount of time that the server will refresh the details of the server manager page. Leave this at 10.
      2. The second check box provides the option to NOT start the server manager automatically at logon., It is a preference but I check this box to stop that action.
    2. On the left side of the Server Manager screen locate and click "Local Server". Now we can verify the standard setting for iTarget.
      1. On the second half of the first section you will see "IE Enhanced Security Configuration". Click the word "On". This will display the option to change security settings for both Administrators and Users. Turn both of them to off using the Radio buttons.
    3. Telnet - On the left hand side click the "Dashboard" tad. Now Click the "Add roles and features". Click "Next" four times until you reach the Features area. Scroll down until you see "Telnet Client" and place a check in the box. Click "Next" one time. Click "Install". Close the Server Manager screen.
  2. IPv6 Disable
    1. The first step in disabling IPv6 is to copy the registry file to the server.
      1. Copy \\univ.pitt.edu\svc\NetAdmin\Software_admin\registry stuff\ipv6 disable.reg → c:\Software
      2. Double click the file you just copied "ipv6 disable.reg" and accept the pop-ups.
      3. Now you need to uncheck the IPv6 option in all NIC cards.
        1. Open the "Network and Internet settings" from the icon located on the bottom right of your screen.
        2. On the right hand side you will see "Change Adapter Options" click that option.
        3. You will see a display of all the NIC cards available. right click on each network interface and chose properties.
        4. When the properties page is displayed scroll down until you see "Internet Protocol Version 6 (TCP/IPv6). Uncheck this box.
        5. Perform step 4 for EVERY NIC showing.
  3. TLS Security Settings
    1. Copy \\univ.pitt.edu\svc\NetAdmin\Software_admin\IISCrypto\IIS Crypto GUI version 3.2.16\IISCrypto.exe → c:\Software
    2. You can double click the program once copied or right click and send a shortcut to desktop and then double click
    3. On the main screen the only options that should be check are:
      1. Server Protocols
        1. TLS 1.2
      2. Ciphers
        1. AES 128/128
        2. AES 256/256
      3. Hashes
        1. SHA
        2. SHA 256
        3. SHA 384
        4. SHA 512
      4. Key Exchanges
        1. PKCS
        2. ECDH
      5. Client Protocols
        1. TLS 1.2
    4. On the Advanced Tab you will see DHE Minimum Key Length. This should be set to 2048
    5. Click the apply button and you MUST reboot for the settings to take effect.
    6. When the server reboots open up IISCrypto and confirm all your settings were saved

 

Feedback and Concerns:

 

If you have any feedback regarding this article, please reach out to hsitkb@pitt.edu.  You can also leave a comment below as well. 

Details

Details

Article ID: 3736
Created
Mon 6/29/26 11:33 AM
Modified
Mon 6/29/26 11:34 AM