UCF STIG Viewer Logo

The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.


Overview

Finding ID Version Rule ID IA Controls Severity
V-81215 WBSP-AS-000160 SV-95929r1_rule Medium
Description
Quality of Protection specifies the security level, ciphers, and mutual authentication settings for the Secure Socket Layer (SSL/TLS) configuration.
STIG Date
IBM WebSphere Traditional V9.x Security Technical Implementation Guide 2018-08-24

Details

Check Text ( C-80887r1_chk )
From the administrative console, navigate to Security >> SSL certificate and key management.

Click "SSL configurations".

Click on each SSL configuration to review.

Under "Additional Properties", click "Quality of protection (QoP)" settings.

If the "Protocol" field does not show "TLSv1.2 or greater", this is a finding.
Fix Text (F-87995r3_fix)
From the administrative console, navigate to Security >> SSL certificate and key management.

Click "SSL configurations".

Click on each SSL configuration.

Under "Additional Properties", click "Quality of protection (QoP)" settings.

At the "Protocol" pull-down menu, select "TLSv1.2 or greater".

Click "OK".

Click "Save".

Restart the DMGR and all the JVMs.