{"id":938,"date":"2016-10-17T18:42:47","date_gmt":"2016-10-17T13:12:47","guid":{"rendered":"http:\/\/www.middlewareprimer.com\/blog\/?p=938"},"modified":"2016-10-17T18:42:47","modified_gmt":"2016-10-17T13:12:47","slug":"ibm-integration-bus-v9-enable-tls-protocol","status":"publish","type":"post","link":"http:\/\/www.middlewareprimer.com\/blog\/2016\/10\/17\/ibm-integration-bus-v9-enable-tls-protocol\/","title":{"rendered":"IBM Integration Bus v9 enable TLS protocol"},"content":{"rendered":"<p>IBM Integration Bus v9 enable TLS protocol information provided for reference.<\/p>\n<p>As part of recent security testing performed for one of the customer, I have seen several set of links provided for IBM Integration Bus v9 product where different technotes mentioned to disable SSLv3 protocol as it is\u00a0vulnerable to Padding Oracle On Downgraded Legacy Encryption (POODLE) attack.<\/p>\n<p>I have mentioned in previous blog entry on the links and references for SSLv3 vulnerability information. Please find below commands that needs to be updated on IBM Integration Bus v9 in order to enable TLS protocol.<\/p>\n<p>SSLv3 protocol is now disabled by default. If you are still using SSLv3, it needs to be disabled. Apply IIB v9 latest fix packs in order to get rid of any attacks.<\/p>\n<p>Please check IBM Technote link <a href=\"http:\/\/www-01.ibm.com\/support\/docview.wss?uid=swg21687678\" target=\"_blank\"><span style=\"text-decoration: underline;\"><strong>here<\/strong><\/span><\/a>.<\/p>\n<p>1. Inbound Connections commands<\/p>\n<p>At broker level<br \/>\nmqsichangeproperties mwpbroker -b httplistener -o HTTPSConnector -n sslProtocol -v TLS<\/p>\n<p>At Execution group level<br \/>\nmqsichangeproperties mwpbroker -e mwpeg -o HTTPSConnector -n sslProtocol -v TLS<\/p>\n<p>For TCIPServer<br \/>\nmqsichangeproperties mwpbroker -c TCPIPServer -o myTCPIPServerService -n SSLProtocol\u00a0 -v TLS<\/p>\n<p>For webadmin<br \/>\nmqsichangeproperties mwpbroker -b webadmin -o HTTPSConnector -n sslProtocol -v TLS<\/p>\n<p>Report the properties after modifying the changes,<\/p>\n<p>At broker level for httplistener<br \/>\nmqsireportproperties mwpbroker -b httplistener -o HTTPSConnector\u00a0 -a<br \/>\nmqsireportproperties mwpbroker -b httplistener -o AllReportableEntityNames -a<br \/>\nmqsireportproperties mwpbroker -b httplistener -o HTTPListener -a<\/p>\n<p>At EG level<br \/>\nmqsireportproperties mwpbroker -e mwpeg -o HTTPSConnector -r<\/p>\n<p>Below screenshots for reference performed for Broker and EG level,<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-945 size-full\" src=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl1.png\" alt=\"IBM Integration Bus v9 enable TLS protocol\" width=\"906\" height=\"593\" srcset=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl1.png 906w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl1-300x196.png 300w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl1-768x503.png 768w\" sizes=\"auto, (max-width: 906px) 100vw, 906px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-947 size-full\" src=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl3.png\" alt=\"IBM Integration Bus v9 enable TLS protocol\" width=\"851\" height=\"672\" srcset=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl3.png 851w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl3-300x237.png 300w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl3-768x606.png 768w\" sizes=\"auto, (max-width: 851px) 100vw, 851px\" \/><br \/>\n2. If you want to enable TLS protocol, TLSv1.2 then use below command (applies to other set of commands)<\/p>\n<p>mqsichangeproperties mwpbroker -b httplistener -o HTTPSConnector -n sslProtocol -v TLSv1.2<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-946 size-full\" src=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl2.png\" alt=\"IBM Integration Bus v9 enable TLS protocol\" width=\"943\" height=\"593\" srcset=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl2.png 943w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl2-300x189.png 300w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl2-768x483.png 768w\" sizes=\"auto, (max-width: 943px) 100vw, 943px\" \/><\/p>\n<p>3. To re-enable SSLv3 protocol, please use below commands.<\/p>\n<p>mqsichangeproperties mwpbroker -o BrokerRegistry -n allowSSLv3 -v true<br \/>\nmqsichangeproperties mwpbroker -e mwpeg -o ComIbmJVMManager -n allowSSLv3 -v true<br \/>\nmqsichangeproperties mwpbroker -b httplistener -o HTTPListener -n allowSSLv3 -v true<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-948 size-full\" src=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl4.png\" alt=\"IBM Integration Bus v9 enable TLS protocol\" width=\"887\" height=\"37\" srcset=\"http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl4.png 887w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl4-300x13.png 300w, http:\/\/www.middlewareprimer.com\/blog\/wp-content\/uploads\/2016\/10\/iibssl4-768x32.png 768w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IBM Integration Bus v9 enable TLS protocol information provided for reference. As part of recent security testing performed for one of the customer, I have seen several set of links provided for IBM Integration Bus v9 product where different technotes mentioned to disable SSLv3 protocol as it is\u00a0vulnerable to Padding Oracle On Downgraded Legacy Encryption [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[121,146,275,280,281],"class_list":["post-938","post","type-post","status-publish","format-standard","hentry","category-ibm-integration-bus","tag-critical-cannot-make-ssl-connection","tag-iib-v9","tag-sslv3","tag-tls","tag-tlsv1-2"],"_links":{"self":[{"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/posts\/938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/comments?post=938"}],"version-history":[{"count":4,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/posts\/938\/revisions"}],"predecessor-version":[{"id":1064,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/posts\/938\/revisions\/1064"}],"wp:attachment":[{"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/media?parent=938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/categories?post=938"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.middlewareprimer.com\/blog\/wp-json\/wp\/v2\/tags?post=938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}