Forum Discussion
About Cipher Suites
Hello experts,
We've been doing SSL LAB scans lately.
We found that with the same certificate and the same client ssl profile settings, the scanning results are not the same.
The strange thing is that according to the following article
https://my.f5.com/manage/s/article/K12982
What I see is that F5 is not yet supported by secp521r1.
Why does the scanned result have secp521r1?
1 Reply
Are you doing SSL offloading on that VIP? If your VIP is not doing full SSL offload (e.g., SSL Passthrough or using a transparent profile), the curve seen could be coming from the backend server, not F5.
openssl s_client -connect <IP>:443 -curves secp521r1
If the VIP is truly terminating SSL and does not support secp521r1, the handshake should fail. If the backend server supports it, the same test against it directly will succeed. This should help isolate whether the F5 or the backend is advertising support for that curve.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com