WBSP-AS-000160 - The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Quality of Protection specifies the security level, ciphers, and mutual authentication settings for the Secure Socket Layer (SSL/TLS) configuration.

Solution

From the administrative console, navigate to Security >> SSL certificate and key management.

Click 'SSL configurations'.

Click on each SSL configuration.

Under 'Additional Properties', click 'Quality of protection (QoP)' settings.

At the 'Protocol' pull-down menu, select 'TLSv1.2 or greater'.

Click 'OK'.

Click 'Save'.

Restart the DMGR and all the JVMs.

See Also

http://iasecontent.disa.mil/stigs/zip/U_IBM_WebSphere_Traditional_V9-x_V1R1_STIG.zip