In this article:
Objective
Prerequisites
Steps to follow
Validation and confirmation
Tips
Related topics and articles
Objective
This article explains how to disable the TLS 1.0 and TLS 1.1 protocols in ManageEngine ADAudit Plus. Disabling these outdated protocols strengthens your network security by ensuring communication only occurs over the more secure TLS 1.2 protocol.
Prerequisites
Before proceeding, ensure the following requirements are met:
Access to the ADAudit Plus server.
Administrator privileges on the system running ADAudit Plus.
SSL must be enabled in ADAudit Plus:
Navigate to Admin > General Settings > Connection.
Ensure Enable SSL Port [https] is checked.
Click Save.
Stop the ADAudit Plus service before making configuration changes.
Steps to follow
1. Backup and Edit server.xml
Navigate to:
<Installation Directory>\ADAudit Plus\conf\
Take a backup of the server.xml file.
Open the file using a text editor (e.g., Notepad++ or VS Code).
2. Update SSL Protocols in server.xml
Locate the <Connector> tag near the bottom of the file.
Replace the following line:
sslProtocols="TLSv1,TLSv1.1,TLSv1.2"
With this:
sslenabledProtocols="TLSv1.2"
3. Update Cipher Suites in server.xml
In the same <Connector> tag, update the ciphers attribute with the following:
ciphers="TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
TLS_RSA_WITH_AES_128_CBC_SHA256,
TLS_RSA_WITH_AES_128_CBC_SHA,
TLS_RSA_WITH_AES_256_CBC_SHA256,
TLS_RSA_WITH_AES_256_CBC_SHA"
Save and close the server.xml file.
4. Edit wrapper.conf
Navigate to:
<Installation Directory>\ADAudit Plus\conf\
Backup the wrapper.conf file.
Open it in a text editor.
Search for any entries containing TLSv1 or TLSv1.1 and remove them.
5. Edit servicemonitor.bat
Navigate to:
<Installation Directory>\ADAudit Plus\bin\
Open servicemonitor.bat in a text editor.
Remove any TLSv1 or TLSv1.1 references.
6. Restart ADAudit Plus
Start the ADAudit Plus service using services.msc.
Validation and confirmation
After starting ADAudit Plus, open a browser and navigate to the application using https.
Confirm that the site loads without errors and that only TLS 1.2 is negotiated using browser developer tools or SSL checking tools.
Tips
Regularly audit configuration files for compliance and best practices.
Document the changes for future internal audits.
Related topics and articles