Forum Discussion
can we open login f5 through http and block https? so will not get SSL error.
All 3 vulnerabilities are due to the device self-signed cert created by the BigIP during setup. This can be replaced with a CA-signed cert, this can be a purchased public cert or an internal CA; any self-signed cert will fail your security test. The link I sent earlier will provide those instructions. You'll want to make sure the cert you create of course matches the FQDN/Device name of the BigIP and then you should be able to pass those vulns.
The F5 support site has a lot of good information on creating these certificates depending on what type of module config your using.
https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-concepts-11-4-0/12.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com