Our company recently purchased a 128-bit global SSL certificate from Verisign. I installed it on our IIS 4.0 server and bound it to the proper website. I have configured the site to require SSL and only allow 128-bit connections.
The problem I have is that 40-bit Domestic US browsers (IE and Netscape) upshift to 128-bit encryption even though they are 40-bit.
We have a project participant that is refusing to use the site because of this because they think it is allowing 40-bit connections.Is there a way I can prevent the 40-bit Domestice versions of the browsers from being accepted? Thanks.