Forum Discussion
An Irule for Client Ssl Profile that Allows Unassigned TLS Extension Values (17516)
As brilliant as this is.Is it possible that post-quantum cryptography may be a stumbling block to this solution, by causing tcp fragmentation. With Clienthello packets of 540bytes, this worked perfectly. An example is the "Extension Unknown Type 17516" added there.
Recent tests show the extension addition is no longer working. The only significant change is that CLIENTSSL HELLO packets are now fragmented on TLS 1.3 with the Post-Quantum Cryptography implementation on clients (browsers), with CLIENTSSL HELLO now regularly abover 1500 bytes causing fragmentation.
is it possible if F5 is Client-side server to force all clients to use X25519 ciphers instead of X25519Kyber512Draft00 and X25519Kyber768 X25519MLKEM768 to ensure that full flow is not broken. is there any changes on CLIENTSSL Profile to implement this.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com