Skip Navigation

IIST-SI-000228: Prohibit non-ASCII characters in URLs

Non-ASCII characters in URLs must be prohibited by any IIS 10.0 website.
To check compliance with IIST-SI-000228, complete the following steps for each site hosted on the IIS 10.0 web server:
  1. Open the IIS 10.0 Manager.
  2. Click the site name.
  3. Double-click the
    Request Filtering
    icon.
  4. In the
    Actions
    pane, click
    Edit Feature Settings
    .
If the
Allow high-bit characters
option is selected, your application is not compliant.
If this IIS 10.0 installation supports Microsoft Exchange, and is not otherwise hosting any content, this requirement is not applicable.
If your application is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the site name.
  3. Double-click the
    Request Filtering
    icon.
  4. In the
    Actions
    pane, click
    Edit Feature Settings
    .
Deselect the
Allow high-bit characters
option.