6.5 Ensure sslProtocol is set to TLS for Secure Connectors (verify sslProtocol is set to TLS)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The sslProtocol setting determines which protocol Tomcat will use to protect traffic. It is recommended that sslProtocol attribute be set to TLS.

Solution

In server.xml, set the sslProtocol attribute to 'TLS' for Connectors having SSLEnabled set to true.

See Also

https://workbench.cisecurity.org/files/267

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: e196f7b24db9f6c5255f9c55bbdbd492c0763f6399bfc86533fbc562b102f264