With all the recent discussions on SSL due to the OpenSSL bug and the process to verify our iSeries was not affected by this, we had one scanning site make a strong recommendation to enable TLS 1.2 support. I know that as of V7.1 IBM did add TLS 1.2 support and found reference to how to enable it. In looking at our system I noticed that system value QSSLCLSCTL is set to *USRFDN and I do not know how long it has been that way. It may have been from before we upgraded from V5R4 to V7.1, which if I read IBM docs correctly, means the Cipher list in QSSLCSL would not get automatically updated on an upgrade and just adding TLS 1.1 and TLS 1.2 support on QSSLPCL would not add to the Cipher list automatically.
So beings be to two questions before I fully enable TLS 1.2.
1) Has anyone else done this and if so, were there any gotchas to be aware of?
2) Is this the complete list of all current Cipher's that should be defined?
Some of my reference links
Pennsylvania College of Technology