{"id":631,"date":"2016-10-12T22:06:22","date_gmt":"2016-10-12T22:06:22","guid":{"rendered":"http:\/\/wp.andreas.bieri.name\/myblog\/?p=631"},"modified":"2016-10-12T22:06:22","modified_gmt":"2016-10-12T22:06:22","slug":"tlsssl-konfigurieren-cipher-suites-abschalten","status":"publish","type":"post","link":"http:\/\/52.29.166.97\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/","title":{"rendered":"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE)"},"content":{"rendered":"<h3>Worum es geht<\/h3>\n<p>Skype for Business &#8211; oder allgemeiner ein Windows Server &#8211; exponiert eine Reihe von (Web-) Schnittstellen, die mit teilweise l\u00e4ngst veralteten Protokollen und Verschl\u00fcsselungsmethoden (Cipher Suites) ausger\u00fcstet sind. \u00a0Als Best Practice sind &#8211; soweit m\u00f6glich &#8211; nur die Protokolle der letzten Generation aktiv zu belassen, um sich gegen POODLE Attacken und andere abzusichern.<\/p>\n<p>&nbsp;<\/p>\n<h3>Die Windows Server Defaults<\/h3>\n<p>Der Artikel\u00a0<a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/245030\" target=\"_blank\">https:\/\/support.microsoft.com\/en-us\/kb\/245030<\/a>\u00a0dokumentiert die grundlegenden Einstellungen f\u00fcr den TLS\/SSL Security Provider (SCHANNEL):\u00a0<em>You can use the Windows registry to control the use of specific SSL 3.0 or TLS 1.0 cipher suites with respect to the cryptographic algorithms that are supported by the Base Cryptographic Provider or the Enhanced Cryptographic Provider. Windows Server 2008 supports the following protocols:<\/em><\/p>\n<ul>\n<li><em>SSL 2.0<\/em><\/li>\n<li><em>SSL 3.0<\/em><\/li>\n<li><em>TLS 1.0<\/em><\/li>\n<\/ul>\n<p><em>Windows Server 2008 R2 and Windows 7 support the following protocols:<\/em><\/p>\n<ul>\n<li><em>SSL 2.0<\/em><\/li>\n<li><em>SSL 3.0<\/em><\/li>\n<li><em>TLS 1.0<\/em><\/li>\n<li><em>TLS 1.1<\/em><\/li>\n<li><em>TLS 1.2<\/em><\/li>\n<\/ul>\n<p><em>These protocols can be disabled for the server or client architecture. This means the protocol can be omitted or disabled as follows:<\/em><\/p>\n<ul>\n<li><em>The protocol can be <strong>omitted<\/strong> from the list of supported protocols that are included in the <strong>Client Hello<\/strong> when an SSL connection is started.<\/em><\/li>\n<li><em>The protocol can be <strong>disabled on the server<\/strong> so that the server will not respond by using that protocol even if a client requests SSL 2.0.<\/em><\/li>\n<\/ul>\n<p>Noch weitergehende Details enth\u00e4lt\u00a0<a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/dn786418.aspx\" target=\"_blank\">https:\/\/technet.microsoft.com\/en-us\/library\/dn786418.aspx<\/a>\u00a0 (Updated: November 5, 2015).<\/p>\n<div id=\"mainSection\">\n<div id=\"mainBody\">\n<h3 class=\"introduction\"><\/h3>\n<h3 class=\"introduction\">Lync und Skype for Business<\/h3>\n<div class=\"introduction\">\n<ul>\n<li>SSL\/TLS\/MTLS:\u00a0<a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/dn481135.aspx\" target=\"_blank\">Skype for Business Server 2015: Encryption<\/a><\/li>\n<\/ul>\n<\/div>\n<p>F\u00fcr die Webservices kann eine Konfiguration auf dem Reverse Proxy erfolgen; f\u00fcr die Edge Server, die in der Regel ihre Schnittstellen hinter einer Port-based Firewall anbieten (keine Proxy Funktion) ist in jedem Fall die Registry anzupassen.\u00a0Die Protokolle SSL 2.0 und SSL 3.0 sollten gegen aussen komplett abgeschaltet werden. In der Regel kann man dies auch firmen-intern tun. Aufmerksamkeit sollte man auch den Cipher Suites schenken. Bei denen kann man bedenkenlos auf jeden Fall RC4 entfernen.<\/p>\n<p>Eine standard Einstellung auf dem Edge Server ist wie folgt:<\/p>\n<pre>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL]\n\"EventLogging\"=dword:00000001\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Ciphers]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Ciphers\\RC4 128\/128]\n\"Enabled\"=dword:00000000\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\CipherSuites]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Hashes]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\KeyExchangeAlgorithms]\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\SSL 2.0]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\SSL 2.0\\Client]\n\"DisabledByDefault\"=dword:00000001\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\SSL 2.0\\Server]\n\"Enabled\"=dword:00000000\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\SSL 3.0]\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\SSL 3.0\\Server]\n\"Enabled\"=dword:00000000<\/pre>\n<p>Optional kann explizit noch TLS1.2 aktiviert werden, default ist TLS 1.0 und 1.1 aktiv (analoge Einstellugen gibt es f\u00fcr TLS 1.1 und 1.0).<\/p>\n<pre>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\Protocols\\TLS 1.2\\Server\n\"Enabled\"=dword:0xfffffffff\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 (4294967295)\n\"DisabledByDefault\"=dword:00000000<\/pre>\n<p>F\u00fcr die Bedeutung der Keys kommt der eingangs erw\u00e4hnte KB Artikel zu Hilfe:<\/p>\n<\/div>\n<ul>\n<li>Using the<strong> Enabled = 0x0 registry setting disables the protocol.<\/strong> This setting cannot be overwritten&#8230;<\/li>\n<li>Using the <strong>DisabledByDefault registry setting only prevents that protocol from issuing the Hello command<\/strong> over that protocol when an SSL connection with a server is initiated. This setting <strong>can be overwritten<\/strong>\u00a0&#8230;..<\/li>\n<\/ul>\n<p><strong>Deshalb ist die richtige Einstellung: To prevent a protocol from being used, use the Enabled = 0x0 setting<\/strong>.<\/p>\n<div id=\"mainBody\">\n<p>&nbsp;<\/p>\n<h3>Praxis<\/h3>\n<p>Nun: Die Erfahrungen aus der Praxis zeigen, dass 3DES nicht ohne weiteres entfernt werden kann, z.B.\u00a0sind Polycom und Audiocodes IP Phones auf 3DES angewiesen, da diese Ger\u00e4te erstaunlicherweise modernere Schl\u00fcsselverfahren wie AES noch gar nicht implementiert haben. Der Hersteller ist informiert.<\/p>\n<p>Testen kann man die Konfiguration mit dem Web Service von Digicert <a href=\"http:\/\/www.digicert.com\/help\" target=\"_blank\">http:\/\/www.digicert.com\/help<\/a>\u00a0(URL eingeben und Check for common vulnerabilities anw\u00e4hlen).<\/p>\n<p><img loading=\"lazy\" class=\"wp-image-1802 aligncenter\" src=\"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png\" alt=\"tls-1\" width=\"570\" height=\"268\" srcset=\"http:\/\/52.29.166.97\/myblog\/wp-content\/uploads\/2016\/04\/tls-1.png 664w, http:\/\/52.29.166.97\/myblog\/wp-content\/uploads\/2016\/04\/tls-1-300x141.png 300w\" sizes=\"(max-width: 570px) 100vw, 570px\" \/><\/p>\n<\/div>\n<\/div>\n<p>Sehr n\u00fctzlich ist auch das Schweizer Taschenmesser IIS Crypto von Nartac, denn<\/p>\n<p><em>&#8230; is a free tool that gives administrators the ability to enable or disable protocols, ciphers, hashes and key exchange algorithms on Windows Server 2008, 2012 and 2016. It also lets you reorder SSL\/TLS cipher suites offered by IIS, implement best practices with a single click, create custom templates and test your website.<\/em><\/p>\n<p style=\"text-align: left;\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-1803\" src=\"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-2.png\" alt=\"tls-2\" width=\"900\" height=\"700\" srcset=\"http:\/\/52.29.166.97\/myblog\/wp-content\/uploads\/2016\/04\/tls-2.png 900w, http:\/\/52.29.166.97\/myblog\/wp-content\/uploads\/2016\/04\/tls-2-300x233.png 300w, http:\/\/52.29.166.97\/myblog\/wp-content\/uploads\/2016\/04\/tls-2-768x597.png 768w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Worum es geht Skype for Business &#8211; oder allgemeiner ein Windows Server &#8211; exponiert eine Reihe von (Web-) Schnittstellen, die mit teilweise l\u00e4ngst veralteten Protokollen und Verschl\u00fcsselungsmethoden (Cipher Suites) ausger\u00fcstet sind. \u00a0Als Best Practice sind &#8211; soweit m\u00f6glich &#8211; nur die Protokolle der letzten Generation aktiv zu belassen, um sich gegen POODLE Attacken und andere [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[35,77,122,131],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.\" \/>\n<meta property=\"og:description\" content=\"Worum es geht Skype for Business &#8211; oder allgemeiner ein Windows Server &#8211; exponiert eine Reihe von (Web-) Schnittstellen, die mit teilweise l\u00e4ngst veralteten Protokollen und Verschl\u00fcsselungsmethoden (Cipher Suites) ausger\u00fcstet sind. \u00a0Als Best Practice sind &#8211; soweit m\u00f6glich &#8211; nur die Protokolle der letzten Generation aktiv zu belassen, um sich gegen POODLE Attacken und andere [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/\" \/>\n<meta property=\"og:site_name\" content=\"Merkbar.\" \/>\n<meta property=\"article:published_time\" content=\"2016-10-12T22:06:22+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"wp_blogadmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#website\",\"url\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/\",\"name\":\"Merkbar.\",\"description\":\"IT, Elektronik und Mathematik\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"de\"},{\"@type\":\"ImageObject\",\"@id\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#primaryimage\",\"inLanguage\":\"de\",\"url\":\"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png\",\"contentUrl\":\"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png\"},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#webpage\",\"url\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/\",\"name\":\"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.\",\"isPartOf\":{\"@id\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#primaryimage\"},\"datePublished\":\"2016-10-12T22:06:22+00:00\",\"dateModified\":\"2016-10-12T22:06:22+00:00\",\"author\":{\"@id\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#\/schema\/person\/47691942dec3f2eb9d34bb8b5507870d\"},\"breadcrumb\":{\"@id\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE)\"}]},{\"@type\":\"Person\",\"@id\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#\/schema\/person\/47691942dec3f2eb9d34bb8b5507870d\",\"name\":\"wp_blogadmin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#personlogo\",\"inLanguage\":\"de\",\"url\":\"http:\/\/1.gravatar.com\/avatar\/d0dc804558b03f640b22e497ec010c9a?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/1.gravatar.com\/avatar\/d0dc804558b03f640b22e497ec010c9a?s=96&d=mm&r=g\",\"caption\":\"wp_blogadmin\"},\"url\":\"http:\/\/52.29.166.97\/myblog\/author\/wp_blogadmin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/","og_locale":"de_DE","og_type":"article","og_title":"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.","og_description":"Worum es geht Skype for Business &#8211; oder allgemeiner ein Windows Server &#8211; exponiert eine Reihe von (Web-) Schnittstellen, die mit teilweise l\u00e4ngst veralteten Protokollen und Verschl\u00fcsselungsmethoden (Cipher Suites) ausger\u00fcstet sind. \u00a0Als Best Practice sind &#8211; soweit m\u00f6glich &#8211; nur die Protokolle der letzten Generation aktiv zu belassen, um sich gegen POODLE Attacken und andere [&hellip;]","og_url":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/","og_site_name":"Merkbar.","article_published_time":"2016-10-12T22:06:22+00:00","og_image":[{"url":"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png"}],"twitter_card":"summary","twitter_misc":{"Verfasst von":"wp_blogadmin","Gesch\u00e4tzte Lesezeit":"4 Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#website","url":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/","name":"Merkbar.","description":"IT, Elektronik und Mathematik","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"de"},{"@type":"ImageObject","@id":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#primaryimage","inLanguage":"de","url":"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png","contentUrl":"http:\/\/wp.andreas.bieri.name\/wp-content\/uploads\/2016\/04\/tls-1.png"},{"@type":"WebPage","@id":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#webpage","url":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/","name":"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE) - Merkbar.","isPartOf":{"@id":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#website"},"primaryImageOfPage":{"@id":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#primaryimage"},"datePublished":"2016-10-12T22:06:22+00:00","dateModified":"2016-10-12T22:06:22+00:00","author":{"@id":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#\/schema\/person\/47691942dec3f2eb9d34bb8b5507870d"},"breadcrumb":{"@id":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/wp.andreas.bieri.name\/myblog\/2016\/10\/12\/tlsssl-konfigurieren-cipher-suites-abschalten\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/"},{"@type":"ListItem","position":2,"name":"TLS\/SSL und Cipher Suites sichern in Skype und Windows (gegen u.a. POODLE)"}]},{"@type":"Person","@id":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#\/schema\/person\/47691942dec3f2eb9d34bb8b5507870d","name":"wp_blogadmin","image":{"@type":"ImageObject","@id":"http:\/\/ec2-52-29-166-97.eu-central-1.compute.amazonaws.com\/myblog\/#personlogo","inLanguage":"de","url":"http:\/\/1.gravatar.com\/avatar\/d0dc804558b03f640b22e497ec010c9a?s=96&d=mm&r=g","contentUrl":"http:\/\/1.gravatar.com\/avatar\/d0dc804558b03f640b22e497ec010c9a?s=96&d=mm&r=g","caption":"wp_blogadmin"},"url":"http:\/\/52.29.166.97\/myblog\/author\/wp_blogadmin\/"}]}},"_links":{"self":[{"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/posts\/631"}],"collection":[{"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/comments?post=631"}],"version-history":[{"count":0,"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/posts\/631\/revisions"}],"wp:attachment":[{"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/media?parent=631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/categories?post=631"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/52.29.166.97\/myblog\/wp-json\/wp\/v2\/tags?post=631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}