Enabling or Disabling TLS Versions
To allow (or restrict) specific TLS protocols for the application to use:
- Stop Cascade CMS.
- Edit the file
tomcat/conf/server.xml. - Locate your existing SSL/TLS Connector.
- Add the
sslEnabledProtocolsattribute along with TLS protocols that you wish to allow/restrict. For example:sslEnabledProtocols="TLSv1.2"- to force TLSv1.2 onlysslEnabledProtocols="TLSv1.2+TLSv1.3"- to allow both TLSv1.2 and TLSv1.3
- Save the file
- Start Cascade CMS
A sample Connector that allows for TLSv1.2 and TLSv1.3 can be seen below:
XML
<Connector SSLEnabled="true" clientAuth="false" compressibleMimeType="application/javascript,application/json,application/rss+xml,application/vnd.ms-fontobject,application/font-sfnt,application/font-woff,font/opentype,font/woff2,application/x-javascript,application/xhtml+xml,application/xml,font/eot,font/opentype,image/svg+xml,image/vnd.microsoft.icon,image/x-icon,text/css,text/html,text/javascript,text/plain,text/xml" compression="on" compressionMinSize="1024" connectionTimeout="20000" keystoreFile="pathToKeystore" keystorePass="keystorePass" maxParameterCount="1000000" maxPostSize="40000000" maxSwallowSize="-1" maxThreads="256" noCompressionUserAgents="gozilla, traviata" port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" scheme="https" secure="true" sslEnabledProtocols="TLSv1.2+TLSv1.3" sslProtocol="TLS"/>
See the official Apache Tomcat documentation for additional information.
Tip
Be sure to document any changes you make to the server.xml file so that you can put them back in place after any future upgrades to the application.