WebSphere Application Server & Liberty

WebSphere Application Server & Liberty

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  TLS 1.2 Support on WebSphere 7.0.0.25

    Posted Thu February 17, 2022 04:57 PM
    I was wondering where we would find out if WebSphere 7.0 supports TLS 1.2 or where we could check on the Admin Console if it's supported.  Any assistance would be appreciated?  I looked at the Admin Configuration and Security documentation to no avail.

    Cesar

    ------------------------------
    Cesar Garcia
    ------------------------------


  • 2.  RE: TLS 1.2 Support on WebSphere 7.0.0.25

    Posted Thu February 17, 2022 06:06 PM
    Edited by Alasdair Nottingham Thu February 17, 2022 06:21 PM
    Please see the response from Jackson. I would strongly recommend upgrading to an in support release running Java 8.

    ------------------------------
    Alasdair Nottingham
    ------------------------------



  • 3.  RE: TLS 1.2 Support on WebSphere 7.0.0.25

    Posted Thu February 17, 2022 06:44 PM
    Hello Alasdair,

    Yes, we hope to be able to upgrade in the near future.  Thanks.

    Cesar

    ------------------------------
    Cesar Garcia
    ------------------------------



  • 4.  RE: TLS 1.2 Support on WebSphere 7.0.0.25

    Posted Thu February 17, 2022 06:08 PM
    Hi Cesar, support for different TLS protocols is dependent on the underlying Java runtime that WebSphere is running on. There were some earlier versions of Java 6, which WebSphere 7 runs on, that did not support TLSv1.2. To check if TLSv1.2 is supported in WebSphere, go to the Security > SSL Certificate and Key Management > SSL Configurations panel, click on any of the SSL Configurations there, and then click on Quality of Protection (QoP) Settings. On that panel there is a dropdown to select the protocol, and it will have TLSv1.2 listed if it is available in the underlying Java runtime. If TLSv1.2 is listed there, but it is not the currently selected protocol, that means it is supported but not currently being used; if this is the case and you want to enable it I would strongly recommend updating to the latest WebSphere v7 and Java 6 fixpacks before trying to enable it.

    ------------------------------
    Jackson Leonard
    ------------------------------



  • 5.  RE: TLS 1.2 Support on WebSphere 7.0.0.25

    Posted Thu February 17, 2022 06:42 PM
    Hello Jackson,

    I appreciate your response.  I do see that TLSv1.2 is an option.  Unfortunately, since this is a vendor provided application, we cannot easily upgrade the WebSphere and Java 6.  What kind of issues can arise if both of these are not upgraded, or do you believe it's not best to enable it without encountering issues with the application.

    Cesar

    ------------------------------
    Cesar Garcia
    ------------------------------