The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.

From IBM WebSphere Traditional V9.x Security Technical Implementation Guide

Part of SRG-APP-000014-AS-000009

Associated with: CCI-000068

SV-95929r1_rule The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.

Vulnerability discussion

Quality of Protection specifies the security level, ciphers, and mutual authentication settings for the Secure Socket Layer (SSL/TLS) configuration.

Check content

From the administrative console, navigate to Security >> SSL certificate and key management. Click "SSL configurations". Click on each SSL configuration to review. Under "Additional Properties", click "Quality of protection (QoP)" settings. If the "Protocol" field does not show "TLSv1.2 or greater", this is a finding.

Fix text

From the administrative console, navigate to Security >> SSL certificate and key management. Click "SSL configurations". Click on each SSL configuration. Under "Additional Properties", click "Quality of protection (QoP)" settings. At the "Protocol" pull-down menu, select "TLSv1.2 or greater". Click "OK". Click "Save". Restart the DMGR and all the JVMs.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer