Support for the transition to NIST SP 800-131A with Web Administration Tool

You must use a supported browser, Web Administration Tool, application server, and IBM® Semeru Runtime Certified Edition version that are required for the transition to NIST SP 800-131A.

To use Web Administration Tool to connect to a directory server that support transition to NIST SP 800-131A, you must meet the following dependencies:

  • Deploy Web Administration Tool in WebSphere® Application Server, Version 9.0.5 or later.
  • Use IBM Semeru Runtime Certified Edition Version 17 SR 0 or later.
  • Use a browser that supports TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 secure communication protocols. The browsers supported for IBM Security Verify Directory, Version 10.0.2 are Internet Explorer, Version 10 or later and Firefox ESR, Version 24 or later.

To support transition to NIST SP 800-131A, Web Administration Tool is dependent on web application server on which it is deployed. WebSphere Application Server uses IBM Semeru Runtime Certified Edition security features to support the required security level.

Note: It is advisable to set the security level on the directory server and WebSphere Application Server as required by your organization.
The following configuration is required to support transition to NIST SP 800-131A with Web Administration Tool:
  1. Install IBM Security Verify Directory, Version 10.0.2. For more information, see Installing and Configuring section.
  2. Install Web Administration Tool and WebSphere Application Server. For more information, see Installing and Configuring section.
  3. Deploy Web Administration Tool in WebSphere Application Server. For more information, see Installing and Configuring section.
  4. Create a CMS key database file for directory server and a JKS key database file for Web Administration Tool. For more information, see Creating a key database file with a self-signed certificate.
  5. Configure a directory server instance with the required protocol and ciphers for secure communication. For more information, see Directory server instance with the SSL and TLS protocols.
  6. Enable TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 secure communication protocols on your browser. For more information, search the introducing TLS v1.2 keyword in the Microsoft™ TechNet website at http://technet.microsoft.com/en-US/.
  7. Configure Web Administration Tool with a JKS key database.
  8. Configure WebSphere Application Server to the security level as required by your organization.

To set and use the Federal Information Processing Standards (FIPS) mode and level of the security standard in Web Administration Tool, use the wsadmin tool of WebSphere Application Server, Version 9.0.5. The following FIPS mode, level of the security standard, and protocols are supported:

Table 1. The relationship between FIPS mode, level of security standard, and protocols

The table lists the relationship between FIPS mode, level of security standard, and protocols that are supported by an application server.

FIPS mode Level of security standard Supported protocols by Web Administration Tool
false None
  • SSL_TLS
  • SSL v3
  • TLS 1.0
  • TLS 1.1
  • TLS 1.2
  • TLS 1.3
true FIPS140-2 mode TLS 1.0
true SP800-131 transition mode
  • TLS 1.0
  • TLS 1.1
  • TLS 1.2
  • TLS 1.3
true SP800-131 strict mode
  • TLS 1.2
  • TLS 1.3
true Suite B 128
  • TLS 1.2
  • TLS 1.3
true Suite B 192
  • TLS 1.2
  • TLS 1.3