Fix (APAR): PI34229 Status: Fix Release: 8.5.5.5,8.5.5.4,8.5.5.3,8.5.5.2 Operating System: AIX,HP-UX,Linux,Solaris,Windows Supersedes Fixes: CMVC Defect: xxxxxx Byte size of APAR: 3370906 Date: 2015-04-08 Abstract: Disable RC4-based TLS ciphers by default in IBM HTTP Server Description/symptom of problem: PI34229 resolves the following problem: ERROR DESCRIPTION: When SSL is enabled with 'SSLEnable', IBM HTTP Server includes RC4-based ciphers in its default ciphers. LOCAL FIX: PROBLEM SUMMARY: RC4 is now considered 'weak', so RC4-based ciphers should not be included in the default list. PROBLEM CONCLUSION: RC4 was removed from the set of default ciphers in V7R0 and later. This fix is targeted for IBM HTTP Server fix packs: - 7.0.0.39 - 8.0.0.11 - 8.5.5.6 Directions to apply fix: Special Instructions: None NOTE: The user must: * Be at V1.4.3 or newer of the Installation Manager. Certain iFixes may require a newer version of the Installation Manager and the Installation Manager will inform you during the installation process if a newer version is required. * Be logged in with the same authority level when unpacking a fix, fix pack, or refresh pack. The IBM Information Center can provide details, if needed, on the use of the Installation Manager to apply the interim fix: http://publib.boulder.ibm.com/infocenter/install/v1r4/index.jsp. 1) Shutdown IBM HTTP Server 2) Apply the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to remove fix: The IBM Information Center can provide details, if needed, on the use of the Installation Manager to remove the interim fix: http://publib.boulder.ibm.com/infocenter/install/v1r4/index.jsp. 1) Shutdown IBM HTTP Server 2) Remove the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to re-apply fix: 1) Stop IBM HTTP Server. 2) Follow the directions to apply the fix. 3) Restart IBM HTTP Server. Additional Information: