This is an IBM Automation portal for Cloud Platform products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
Shape the future of IBM!
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Search existing ideas
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updateson them if they matter to you. If you can't find what you are looking for,
Post your ideas
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Specific links you will want to bookmark for future use
We are using EKMF Web, and it uses WebSphere Liberty. EKMFWEB uses port 9443. Recently we received report that the port is vulnerable. Upon researching with IBM, it was found that weak ciphers have been included in liberty even when configured to only use strong ciphers. That means liberty is not providing strongest security to EKMFWeb.
For a short-term solution, we have edited server.xml file in EKMF to include few strongest ciphers.
However, I would request IBM to make this change to liberty to use strongest ciphers by default, so that one don't have to code it manually. This will help is maintaining the product, because during upgrades, one might forget to add the cipher again to server.xml file and we end getting the audit failure reports again.
Also, strongest ciphers would help everyone who are using WebSphere Liberty. Strongest Ciphers mean stronger security.
Do not place IBM confidential, company confidential, or personal information into any field.