WBSP-AS-000160 - The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.

Information

Quality of Protection specifies the security level, ciphers, and mutual authentication settings for the Secure Socket Layer (SSL/TLS) configuration.

Solution

From the administrative console, navigate to Security >> SSL certificate and key management.

Click 'SSL configurations'.

Click on each SSL configuration.

Under 'Additional Properties', click 'Quality of protection (QoP)' settings.

At the 'Protocol' pull-down menu, select 'TLSv1.2 or greater'.

Click 'OK'.

Click 'Save'.

Restart the DMGR and all the JVMs.

See Also

http://iasecontent.disa.mil/stigs/zip/U_IBM_WebSphere_Traditional_V9-x_V1R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|II, CCI|CCI-000068, Rule-ID|SV-95929r1_rule, STIG-ID|WBSP-AS-000160, Vuln-ID|V-81215

Plugin: Unix

Control ID: 6afacf12c94d61446c5576b88c8b9dc11f9be66a7f81a21a774dfcc52f264709