Forum Discussion
Cipher Suites to Mitigate against Vulnerabilities
Hi,
I would like to know how to mitigate against the below vulnerabilites, running code version 10.2.1
- TLSV1.X Poodle - CVE-2014-8730
- SSLv3 Poodle - CVE-2014-3566
- Beast
3 Replies
- samstep
Cirrocumulus
First of all - have you got the latest Hotfix for 10.2.1?
Also note that some SSL-related vulnerabilities were only patched in SSL profiles starting from v10.2.4...
Check out these articles:
https://devcentral.f5.com/articles/cve-2014-3566-poodle-vs-cve-2014-8730-tls-poodle
https://devcentral.f5.com/articles/cve-2014-3566-poodle-vs-cve-2014-8730-tls-poodle
You can check how good your cipher config is using the SSL Labs test your websites: https://www.ssllabs.com/ssltest/
Hope this helps,
Sam
- Hannes_Rapp
Nimbostratus
Sorry, not possible in v10.2.1 without the use of iRules. Can you upgrade the box to v10.2.4? If yes, I can share a cipher string which will give you a "B" rating in Qualys SSL Labs (this is the max you can get in v10).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com