Tools

How to change the TLS protocol in Web Help Desk

This article describes how to change the Transport Layer Security (TLS) protocol for a Web Help Desk deployment.

First published date

9/15/2020 10:07 PM

Last published date

9/15/2020 10:07 PM

Overview

In Web Help Desk 12.7.3, TLS 1.2 is enabled by default for improved data protection over a network. In some cases, you may need to implement TLS 1.1 to support Federal Information Processing Standards (FIPS) mode or legacy computer systems that do not support the TLS 1.2 protocol.

This article describes how to enable TLS 1.1 in the Apache Tomcat server configuration file. 

Product section

Web Help Desk

Resolution

  1. Stop Web Help Desk.
  2. Navigate to the following directory:
    <WebHelpDesk>\conf

  3. Back up the tomcat_server_template.xml file to a separate location.
    If you encounter any issues, you can revert to the original settings.

  4. Open the tomcat_server_template.xml file in a text editor (such as Notepad).
  5. Locate the WEBHELPDESK_SSL_PORT settings.
  6. Locate sslProtocol in the file. There are two occurrences in the file. 
  7. Add TLSv1.1 to the first occurrence.
    Change:
    clientAuth="false sslProtocol="TLS" sslEnabledProtocols="TLSv1.2"
    to
    clientAuth="false sslProtocol="TLS" sslEnabledProtocols="TLSv1.1, TLSv1.2"

  8. Repeat step 7 for the second occurrence.
  9. Save the file.
  10. Start Web Help Desk.

Verify the TLS version

Verify the TLS version using a Google Chrome or Mozilla Firefox web browser. 


Google Chrome

  1. Log in to Web Help Desk.
  2. Right-click the Web Help Desk interface and select Inspect.
  3. In the toolbar, click Security.
  4. Under Security overview, scroll down and review the connection details. 

Mozilla Firefox

  1. Log in to Web Help Desk.
  2. In the Address bar, click the icon to the left of the URL.
  3. Click More Information.
  4. Click the Security tab.
  5. Scroll down to Technical Details and review the TLS version.