AUSTIN-TLS Settings

AUSTIN-TLS Settings

Overview

The AUSTIN TLS GPO can be used to configure the use of only certain TLS versions and ciphers.

 

When there is a need to edit settings (for example, to remove a cipher), a new GPO will be created. The TLS GPOs are not edited after they are published. The AD team will not edit any of the settings in a specific GPO after it has been announced as available. Departments can then link the new GPO after evaluating the changes and testing them in their environment.

When a new version of the AUSTIN - TLS Settings GPO is published, it will be announced in the System Administrators - Windows Channel of the UT IT Community Team.

 

A restart is required for settings in the GPO to take effect.

GPO List

GPO Name

Last Modified Date

TLS Versions Enabled

Winhttp

.NET Framework

Ciphers

GPO Name

Last Modified Date

TLS Versions Enabled

Winhttp

.NET Framework

Ciphers

AUSTIN-TLS Settings - 20240806

Aug 6, 2024

Server:

  • TLS 1.2

  • TLS 1.3

Client:

  • TLS 1.2

  • TLS 1.3

 

  • TLS 1.2

  • TLS 1.3

  • TLS 1.2

  • TLS 1.3

(Use OS Configuration)

  • TLS_AES_256_GCM_SHA384

  • TLS_AES_128_GCM_SHA256

  • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

  • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

  • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

  • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256