4.2.2 Ensure 'sslProtocol' is set to the latest versions of TLS (Transport Layer Security)

Information

The latest versions of TLS provide drop support for less secure cryptographic features and add support for more advanced cryptographic algorithms.

TLS 1.2 and higher versions are recommended for secure communication.

Solution

Set the sslProtocol attribute version to the latest supported level in all ssl elements to ${server.config.dir}/configDropins/overrides/*.xml

<ssl ...
sslProtocol="TLSv1.2" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: af6a685a8aa81cd7d63c24e24e15cad274467957fb5c687f0cd4987db96a6bdd