Support for the transition to NIST SP 800-131A with Web Administration Tool
You must use a supported browser, Web Administration Tool, application server, and IBM® Semeru Runtime Certified Edition version that are required for the transition to NIST SP 800-131A.
To use Web Administration Tool to connect to a directory server that support transition to NIST SP 800-131A, you must meet the following dependencies:
- Deploy Web Administration Tool in WebSphere® Application Server, Version 9.0.5 or later.
- Use IBM Semeru Runtime Certified Edition Version 17 SR 0 or later.
- Use a browser that supports
TLS 1.0,TLS 1.1,TLS 1.2, andTLS 1.3secure communication protocols. The browsers supported for IBM Security Verify Directory, Version 10.0.2 are Internet Explorer, Version 10 or later and Firefox ESR, Version 24 or later.
To support transition to NIST SP 800-131A, Web Administration Tool is dependent on web application server on which it is deployed. WebSphere Application Server uses IBM Semeru Runtime Certified Edition security features to support the required security level.
- Install IBM Security Verify Directory, Version 10.0.2. For more information, see Installing and Configuring section.
- Install Web Administration Tool and WebSphere Application Server. For more information, see Installing and Configuring section.
- Deploy Web Administration Tool in WebSphere Application Server. For more information, see Installing and Configuring section.
- Create a
CMSkey database file for directory server and aJKSkey database file for Web Administration Tool. For more information, see Creating a key database file with a self-signed certificate. - Configure a directory server instance with the required protocol and ciphers for secure communication. For more information, see Directory server instance with the SSL and TLS protocols.
- Enable
TLS 1.0,TLS 1.1,TLS 1.2, andTLS 1.3secure communication protocols on your browser. For more information, search theintroducing TLS v1.2keyword in the Microsoft™ TechNet website at http://technet.microsoft.com/en-US/. - Configure Web Administration Tool with a
JKSkey database. - Configure WebSphere Application Server to the security level as required by your organization.
To set and use the Federal Information Processing Standards (FIPS) mode and level of the security standard in Web Administration Tool, use the wsadmin tool of WebSphere Application Server, Version 9.0.5. The following FIPS mode, level of the security standard, and protocols are supported:
| FIPS mode | Level of security standard | Supported protocols by Web Administration Tool |
|---|---|---|
false |
None |
|
true |
FIPS140-2 mode |
TLS 1.0 |
true |
SP800-131 transition mode |
|
true |
SP800-131 strict mode |
|
true |
Suite B 128 |
|
true |
Suite B 192 |
|