
pdownesirl (Customer) asked a question.
We have been advised to enable strict TLS 1.2 on our RSA Authentication Manager virtual appliances.
Apart from making sure we have good backups, should we enable the primary first and then the replicas, or is there a more detailed best practice for this procedure. I am concerned about all appliances, primary and replicas getting the configuration around the same time and if I have to disable strict TLS 1.2 do I again revert on the primary first?
Thanks,
Paul
By default, RSA Authentication Manager 8.2 or later deployments use TLS 1.2, however TLS 1.0 and TLS 1.1 are also supported. Authentication Manager supports a strict TLS mode that only uses TLS 1.2 for communication within your Authentication Manager deployment.
You can enable and disable the strict TLS 1.2 mode. To do so, perform the following procedure on the primary instance and each replica instance. Updating the primary instance automatically updates the web tier, but restarting the web tier is required for the changes to take effect.
Before you begin
Procedure
After you finish
Restart the web tier (if applicable).
Note: For Authentication Manager 8.6 and all subsequent patches or upgrades, you should enable Strict TLS mode again after the upgrade by following the procedure outlined above.
I would recommend doing the procedure on your primary first and then any replicas.
Hi Stacey,
What is the procedure to disable TLS1.1 . Is there a document on this
@BinodChetia96281 (Customer) ,
Use this article for the steps to enable or disable strict TLS 1.2 mode.