
Ts865867 (Community Member) asked a question.
Dear Veracode Support Team
We are currently facing issues related to CWE-296: Improper Following of a Certificate's Chain of Trust during our dynamic scan. The flaws appear to be associated with certificate ciphers configured on our Windows Server.
Some of these issues were resolved after we removed a few insecure ciphers from the server; however, a few findings are still being reported for our application.
Project Details:
Framework: .NET Framework 4.8
Technology: ASP.NET Web Application
URL: [Application URL]
Parameter: NONE
Could you please review and share the recommended steps or configuration changes required to fully resolve this issue from the server side?
Thank you for your assistance and guidance.
Best regards,
Thani
.png)
Hi @Ts865867 (Community Member) - Please schedule a consultation call with our team of AppSec Consultants, they will be able to assist you. Log into the Community via the Veracode Platform, then click the Schedule Consultation button on the home screen of the community: