ThinWorld Citrix Knowledgebase

Wednesday, 6 May 2009

Terminal Services Encryption Levels MinEncryptionLevel

Terminal Services encryption Level can be controlled via GPO or Server Settings. Group Policy being the easiest deployment method.

The Setting is found here

Machine Settings\Windows Components\Terminal Services\Encryption and Security

There are 3 levels available

Low - Client to server traffic is encrypted but server to client is not
Client compatible - all traffic encrypted at highest level supported by client
High - All traffic encrypted at 128 bit strength. Client must support this to be able to connect


The registry value this GPO changes is

HKLM\Software\Microsoft\Windows NT\terminal Services
MinEncryptionLevel Where 1-3 are the values to match above (1 being low)