30 - Ensure sslProtocol is set to TLS for Secure Connector

Information

The ssl Protocol setting determines which protocol Jetty will use to protect traffic. It is recommended that sslProtocol attribute be set to TLS.

The TLS protocol does not contain weaknesses that affect other secure transport protocols, such as SSLv1 or SSLv2. Therefore, TLS is leveraged to protect the confidentiality and integrity of data while in transit.

Solution

In server.xml, set the sslProtocol attribute to TLS for all Connectors having SSLEngine set to on.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: 4e52211b87c146dc7c62681e589e1a1def98cc7540161c2f795a605ca0bfe9c4