Automated TLS/SSL Security Hardening for Windows Server
Windows Sunucular için Otomatik TLS/SSL Güvenlik Sıkılaştırma
| 🇬🇧 English | 🇹🇷 Türkçe |
|---|---|
| 📖 English Documentation | 📖 Türkçe Dokümantasyon |
| EN/TLSHardener.ps1 | TR/TLSHardener.ps1 |
TLS SSL Security Hardening Windows Server PowerShell SCHANNEL Cipher Suites PCI-DSS NIST HIPAA CIS TLS 1.3 TLS 1.2 Registry Compliance Encryption Certificate Protocol Vulnerability Security Audit Server Hardening Cryptography AES-GCM SHA256 ECDHE Best Practices Windows Security Network Security SSL Disable TLS Enable Cipher Configuration
TLS SSL Güvenlik Sıkılaştırma Windows Sunucu PowerShell SCHANNEL Şifreleme Paketleri PCI-DSS NIST HIPAA CIS TLS 1.3 TLS 1.2 Registry Uyumluluk Şifreleme Sertifika Protokol Güvenlik Açığı Güvenlik Denetimi Sunucu Sıkılaştırma Kriptografi AES-GCM SHA256 ECDHE En İyi Uygulamalar Windows Güvenliği Ağ Güvenliği SSL Devre Dışı TLS Etkinleştirme Cipher Yapılandırma
🇬🇧 ENGLISH: Always create a system backup before running this script! Registry changes can cause irreversible issues. Test with
-WhatIfparameter first.🇹🇷 TÜRKÇE: Bu scripti çalıştırmadan önce mutlaka sistem yedeği alın! Registry değişiklikleri geri alınamaz sorunlara yol açabilir. Önce
-WhatIfparametresi ile test edin.
| 🇬🇧 Feature | 🇹🇷 Özellik |
|---|---|
| 🔒 Disable SSL 2.0/3.0, TLS 1.0/1.1 | 🔒 SSL 2.0/3.0, TLS 1.0/1.1 devre dışı |
| ✅ Enable TLS 1.2/1.3 | ✅ TLS 1.2/1.3 etkinleştirme |
| 🛡️ GCM-only cipher suites | 🛡️ Sadece GCM cipher suite'leri |
| 🔑 3072-bit DH key minimum | 🔑 Minimum 3072-bit DH anahtarı |
| 📊 PCI-DSS, NIST, HIPAA, CIS compliance | 📊 PCI-DSS, NIST, HIPAA, CIS uyumluluğu |
| 📦 Automatic backup before changes | 📦 Değişiklik öncesi otomatik yedekleme |
| 👁️ Dry-run mode (-WhatIf) | 👁️ Önizleme modu (-WhatIf) |
| 🔄 Rollback support | 🔄 Geri alma desteği |
| 🌐 Remote server support | 🌐 Uzak sunucu desteği |
# Clone repository
git clone https://github.com/tazxtazxedu/TLSHardener.git
cd TLSHardener
# 🇬🇧 English version
.\EN\TLSHardener.ps1 -WhatIf # Preview
.\EN\TLSHardener.ps1 -Profile recommended # Apply
# 🇹🇷 Türkçe versiyon
.\TR\TLSHardener.ps1 -WhatIf # Önizleme
.\TR\TLSHardener.ps1 -Profile recommended # UygulaTLSHardener/
├── 📁 EN/ # 🇬🇧 English scripts & docs
│ ├── TLSHardener.ps1
│ ├── TLSHardener-Verify.ps1
│ ├── TLSHardener-Compliance.ps1
│ ├── TLSHardener-Report.ps1
│ ├── TLSHardener-Clean.ps1
│ ├── README.md
│ ├── 📁 config/ # English profile configs
│ │ ├── strict.json
│ │ ├── recommended.json
│ │ ├── compatible.json
│ │ └── custom.json
│ └── 📁 assets/ # Icons & images
├── 📁 TR/ # 🇹🇷 Türkçe scriptler & dokümanlar
│ ├── TLSHardener.ps1
│ ├── TLSHardener-Verify.ps1
│ ├── TLSHardener-Compliance.ps1
│ ├── TLSHardener-Report.ps1
│ ├── TLSHardener-Clean.ps1
│ ├── README.md
│ ├── 📁 config/ # Türkçe profil yapılandırmaları
│ │ ├── strict.json
│ │ ├── recommended.json
│ │ ├── compatible.json
│ │ └── custom.json
│ └── 📁 assets/ # Icons & images
├── 📄 README.md # This file (bilingual)
├── 📄 LICENSE # MIT License
├── 📄 CHANGELOG.md # Version history
├── 📄 CONTRIBUTING.md # Contribution guide
└── 📄 SECURITY.md # Security policy
| Standard | Status | Description |
|---|---|---|
| PCI-DSS v4.0 | ✅ | Payment Card Industry Data Security |
| NIST SP 800-52 | ✅ | TLS Implementation Guidelines |
| HIPAA | ✅ | Healthcare Security Requirements |
| CIS Benchmark | ✅ | Windows Server Hardening |
| GDPR | ✅ | Data Protection (Encryption) |
This project is licensed under the MIT License - see LICENSE for details.
Bu proje MIT Lisansı altında lisanslanmıştır - detaylar için LICENSE dosyasına bakın.
See CONTRIBUTING.md for guidelines.
Katkı rehberi için CONTRIBUTING.md dosyasına bakın.
- GitHub: tazxtazxedu/TLSHardener
- Issues: Report a bug / Hata bildir
⭐ Star this repo if it helped you! / Yardımcı olduysa yıldız verin! ⭐
Made with ❤️ for Windows Server Security