Forum Discussion
Kiran_145850
Nimbostratus
Feb 17, 2015Adding Cipher suite "TLS_RSA_WITH_AES_128_CBC_SHA"
Need one information regarding addition of cipher suite to the existing client ssl profile .
Due to poodle vulnerability changed the cipher suite from default to RC4-SHA . Currently need to add one m...
MegaZone
SIRT
Feb 18, 2015ALL ciphers except for RC4 are vulnerable to CVE-2014-8730. (AES-GCM is not, but BIG-IP doesn't support that until 11.5.0.) Unless you have a patched release (as per SOL15882) the ONLY non-vulnerable cipher is RC4. All other ciphers are CBC-mode, even if they don't have 'CBC' in the name, and all CBC ciphers are vulnerable.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects