Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

(RESOLVED) help with tomcat ciphers and nessus scans

I'm being told by the nessus scanning tool that the SSL ciphers offered by my RTC instance on tomcat are too low.

I've gone to the tomcat and jsse references and added a cipers= string to my ssl connector config in /tomcat/conf/server.xml, but I'm not seeing any difference in scan results. I also see nothing in any logs about ciphers, ssl or other security related failures, but I may not be looking where I should.

Can anybody point me in a positive direction for this?

0 votes



One answer

Permanent link
Fixing my own problem... Moving the ciphers line to the UNCOMMENTED connector block for port 9443 makes all the difference in the world!

0 votes

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Feb 03 '11, 4:58 p.m.

Question was seen: 7,241 times

Last updated: Feb 03 '11, 4:58 p.m.

Confirmation Cancel Confirm