6.6

Table Of Contents
Verify the Correct Use of Cipher Suites in Apache HTTPD
For maximum security, verify the correct use of cipher suites in Apache hpd.
Procedure
1 To verify the correct use of cipher suites in Apache hpd, run the grep
SSLCipherSuite /usr/lib/vmware-vcopssuite/utilities/conf/vcops-apache.conf | grep -v '#'
command from the command prompt.
If Apache hpd uses the correct cipher suites, the command returns the following output:
SSLCipherSuite kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES:!aNULL!ADH:!
EXP:!MD5:!3DES:!CAMELLIA:!PSK:!SRP:!DH
2 To congure the correct use of cipher suites, run the sed -i "/^[^#]*SSLCipherSuite/
c\SSLCipherSuite kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES:\!aNULL\!
ADH:\!EXP:\!MD5:\!3DES:\!CAMELLIA:\!PSK:\!SRP:\!DH" /usr/lib/vmware-
vcopssuite/utilities/conf/vcops-apache.conf command from the command prompt.
Run this command if the output in Step 1 is not as expected.
This command disables all cipher suites that use DH and DHE key exchange methods.
3 Run the /etc/init.d/apache2 restart command from the command prompt to restart the Apache2
server.
4 To reenable DH, remove !DH from the cipher suites by running the sed -i "/^[^#]*SSLCipherSuite/
c\SSLCipherSuite kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES:\!aNULL\!
ADH:\!EXP:\!MD5:\!3DES:\!CAMELLIA:\!PSK:\!SRP" /usr/lib/vmware-
vcopssuite/utilities/conf/vcops-apache.conf command from the command prompt.
5 Run the /etc/init.d/apache2 restart command from the command prompt to restart the Apache2
server.
Verify the Correct Use of Cipher Suites in GemFire TLS Handler
For maximum security, verify the correct use of cipher suites in GemFire TLS Handler.
Procedure
1 To verify that the cipher suites are enabled, run the following commands on each node to verify that the
protocols are enabled:
grep cluster-ssl-ciphers /usr/lib/vmware-vcops/user/conf/gemfire.properties | grep -v '#'
grep cluster-ssl-ciphers /usr/lib/vmware-vcops/user/conf/gemfire.native.properties | grep -v
'#'
grep cluster-ssl-ciphers /usr/lib/vmware-vcops/user/conf/gemfire.locator.properties | grep -v
'#'
2 Congure the correct cipher suites.
a Navigate to the administrator user interface at URL/admin.
b To bring the cluster oine, click Bring .
Chapter 3 Secure Configuration of vRealize Operations Manager
VMware, Inc. 23