Configuring advanced TLS security settings

Procedure
  1. From the System Utilities screen, select System Configuration > BIOS/Platform Configuration (RBSU) > Server Security > TLS (HTTPS) Options > Advanced Security Settings.
  2. Configure options.
    • To configure which cipher suites are allowed for TLS connections:

      1. Select Cipher suites allowed for TLS connections.

      2. Select one of the following:

        • Individual check boxes for the cipher suites you want to allow.

        • Select Platform Default Cipher suites

      3. Select Commit changes and exit.

    • To configure the certificate validation process for every TLS connection:

      1. Select Certificate validation process for every TLS connection.

      2. Select a setting:

        • PEER (recommended)—The certificate presented by the peer is validated for secure communication.

        • NONE—Does not validate the certificate.

    • To enable or disable strict host name checking:

      1. Select Strict Hostname checking.

      2. Select a setting:

        • ENABLE—The host name of the connected server is validated with the host name in the certificate supplied by the server.

        • DISABLE—The host name of the connected server is not validated with the host name in the certificate supplied by the server.

    • To specify which protocol version to use for TLS connections:

      1. Select TLS Protocol Version Support.

      2. Select a setting:

        • AUTO—Negotiates the highest protocol version that is supported by both the TLS server and the client.

        • 1.0—Uses TLS protocol version 1.0. (Not supported in Gen10 Plus)

        • 1.1—Uses TLS protocol version 1.1. (Not supported in Gen10 Plus)

        • 1.2—Uses TLS protocol version 1.2.

  3. Save your changes.