The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.
An XCCDF Rule
Description
Quality of Protection specifies the security level, ciphers, and mutual authentication settings for the Secure Socket Layer (SSL/TLS) configuration.
- ID
- SV-95929r1_rule
- Version
- WBSP-AS-000160
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
From the administrative console, navigate to Security >> SSL certificate and key management.
Click "SSL configurations".
Click on each SSL configuration.