IBM Support

webMethods Knowlegebase : SSL Configuration - Disable Weak Diffie–Hellman Cipher Suites (1792966)

Troubleshooting


Problem

Customer recently received a report that the server is supporting weak Diffie–Hellman cipher suites across their environments. Minimum cipher/prime must be 2048 bits. More information about Weak Diffie–Hellman: https://weakdh.org/

The remediation steps recommended by the cyber security team involves us editing the server.xml file to include connector to disable these weak ciphers.

URL reference: https://weakdh.org/sysadmin.html (please see Apache Tomcat for more details on the parameter details)

They have applied these under this file path: <SoftwareAG>/profiles/LJP/configurations/tomcat/conf/server.xml

However, it is not working.

Document Location

Worldwide

[{"Line of Business":{"code":"","label":""},"Business Unit":{"code":"","label":""},"Product":{"code":"SSI42O","label":"IBM webMethods AgileApps SaaS"},"ARM Category":[{"code":"a8mKe00000000AQIAY","label":"webMethods AgileApps Cloud (LJP)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"SUSE Linux Enterprise Server"}],"Version":"10.9"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
20 March 2025

UID

ibm17204605