CipherSpecs and CipherSuites in IBM MQ

From IBM® MQ 8.0.0, Fix Pack 9, IBM MQ supports TLS V1.2 CipherSpecs, and RSA and Diffie-Hellman algorithms. However, you can enable deprecated CipherSpecs, if you need to do so.

See CipherSpec values supported in IBM MQ for information on:
  • CipherSpecs supported by IBM MQ
  • How you enable deprecated CipherSpecs

IBM MQ supports the RSA and Diffie-Hellman key exchange and authentication algorithms. The size of the key used during the TSL, or SSL handshake can depend on the digital certificate you use, but some CipherSpecs include a specification of the handshake key size. Larger handshake key sizes provide stronger authentication. With smaller key sizes, the handshake is faster.