Forum Discussion
jmanya_44531
Feb 14, 2017Nimbostratus
clientssl profile with ECC certificate needs RSA Certificate
Hello guys,
Hope you could support me in the following matther.
I have already purchased an ECC wildcard certificate and I wanted to attach it to a virtual server in my BIG IP 4200 LTM box ...
Kevin_K_51432
Historic F5 Account
Greetings, It looks like at least one RSA cert & key is required. You could try preferring ECC, instead of only using (as above) with:
ECDH_ECDSA:DEFAULT
I would assume BIG-IP bases which cert / key to use based on the client's preference in the initial handshake.
Kevin
Kevin_K_51432
Mar 08, 2017Historic F5 Account
Hi Jorge, The server chooses the cipher suite. So if the client prefers RSA, but supports ECC, BIG-IP will still choose the ECC certificate based on:
ECDH_ECDSA:DEFAULT
Kevin
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects