<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to configure IAG to use AES 256 encryption</title><link>http://blogs.technet.com/edgeaccessblog/archive/2009/05/14/how-to-configure-iag-to-use-aes-256-encryption.aspx</link><description>By default client browsers (or at least, any reasonably up to date client browser) will connect to IAG using 128 Bit encryption. This can be seen by right clicking in the browser pane and choosing ‘Properties’ after you have accessed your IAG portal.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: How to configure IAG to use AES 256 encryption</title><link>http://blogs.technet.com/edgeaccessblog/archive/2009/05/14/how-to-configure-iag-to-use-aes-256-encryption.aspx#3286648</link><pubDate>Tue, 13 Oct 2009 23:33:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3286648</guid><dc:creator>Hank Cohen</dc:creator><description>&lt;p&gt;Do any of the other encryption controls in the OS effect IAG?&lt;/p&gt;
&lt;p&gt;For example the local security policy: &amp;nbsp;secpol.msc&lt;/p&gt;
&lt;p&gt;&amp;quot;System cryptography: Use FIPS compliant algtorithms for encryptio, hashing, and signing.&amp;quot;&lt;/p&gt;
&lt;p&gt;That control is supposed to restrict the system to using the FIPS 140 crypto module. &amp;nbsp;Schannel is supposed to use this restriction. &amp;nbsp;However if you set that policy without this hotfix then you will still get RC4 which is not FIPS in any keylength.&lt;/p&gt;
&lt;p&gt;Installing this patch makes IAG negotiate AES 128 which is FIPS compliant even if the &amp;quot;use FIPS&amp;quot; local policy is not enabled.&lt;/p&gt;
&lt;p&gt;What I really want to know is if installing this patch results in IAG using the FIPS certified crypto service provider?&lt;/p&gt;
</description></item></channel></rss>