Forum Discussion
Diffie-Hellman "p" length 1024/2048 bits
- Dec 07, 2020
When it comes to handshake, the ciphers alone play role in negotiation. The certificate has no play here.
The DHE suites are 1024 alone in F5, if you had seen a 2048 bit, It should have been ECDHE.
Can you put a logging rule to confirm if it indeed was DHE suite and not ECDHE ?
When it comes to handshake, the ciphers alone play role in negotiation. The certificate has no play here.
The DHE suites are 1024 alone in F5, if you had seen a 2048 bit, It should have been ECDHE.
Can you put a logging rule to confirm if it indeed was DHE suite and not ECDHE ?
- rafaelbnDec 07, 2020
Cirrostratus
Hello Jaikumar! Thanks for the reply.
I will investigate it further. But will let you know.
Do you recommend any article/training that explain this? I wish to understand this type of thing better.
Thanks!
- jaikumar_f5Dec 07, 2020
Noctilucent
Here mate, hope this helps.
SSL Profiles Part 1: Handshakes
Troubleshooting SSL/TLS handshake failures
Troubleshooting Handshake by Capturing Traffic
Qualsys SSL lab test reports a result of DH 1024 bits WEAK
- rafaelbnDec 10, 2020
Cirrostratus
Thanks Jaikumar!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
