IBM Support

VULNERABILITY DETECTED: TLS V1.0 ALLOWED IN PORT 16019

Troubleshooting


Problem

TLS 1.0 and 1.1 are showing as available on port 16019.
We have already run "grdapi disable_deprecated_protocols" and it's disabled on all systems.
xxx.ibm.com> grdapi get_secured_protocols_info
ID=0
Deprecated protocols disabled on CM
Comparing versions of CM to 10.1.4
Comparing versions of 80 MUs to 10.1.4
Retrieving STAP info from MUs
Deprecated protocols disabled on guardiumxx1.ibm.com
.
.
Deprecated protocols disabled on guardiumxx5.ibm.com

Resolving The Problem

Resolution Description:
from the cli:
grdapi disable_deprecated_protocols
restart gui
Then, if the CAS service is not used, run CLI command:
11.3 & 11.4: store system service_status cas disable
11.5: store system service disable cas

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m0z000000Gp0RAAS","label":"VULNERABILITY ASSESSMENT"}],"ARM Case Number":"TS012563244","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
12 September 2023

UID

ibm17024964