Forum Discussion
MODdev_119626
Nimbostratus
Mar 11, 20142-way SSL (Client) and Renegotiation
Greetings! We have clients that use 2-way SSL on some of their pages/paths. One of the clients has recently ran a security scan and asked us we remove SSL renegotiation from their profile. Disabling ...
Cory_50405
Noctilucent
Mar 11, 2014On the SSL server profile, change Secure Renegotiation to 'require' or 'require strict' in order to disable insecure negotiation. Keep in mind that if the back end server isn't patched for this, it could break SSL connections through the LTM.
Cory_50405
Noctilucent
Mar 12, 2014The server should be patched for the SSL/TLS renegotiation vulnerability listed here: https://tools.ietf.org/html/rfc5746
If you need client certificate based authentication, I recommend you use proxy SSL. You enable it within both the client and SSL profiles.
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13385.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects