Forum Discussion
Gustavo_Lazarte
Nimbostratus
Jan 13, 2009Disable SSL 2.0
According to our security Auditor we need to disable SSl 2.0 support and support SSL 3.0 or TLS 1.0 instead. I have not found a place in the Client ssl to set this up. I found the following values in ...
Hamish
Cirrocumulus
Jan 13, 2009You can disable SSLv2 in two places in the client SSL setup.
In the options, you can disable sslv2. (Select options, and then scroll down to 'No SSLv2' in the options list that appears. Select that & select 'Enable'. The 'No SSLv2' option will now be listed in the Enabled Options.
Or you can set no SSLv2 in the 'Ciphers' list. I usually set the clientssl profile (The one all other are usually set to inherit from) to
'DEFAULT,!SSLv2,!EXPORT56,!MD5'
Which disables SSLv2, disables 56-bit encryption (For some REALLY old IE browsers that can stepup from 40bit to 128, but can't do 56 to 128 bit step), and lastly disabled MD5 (Because it's broken - As in insecure not as in a bad implementation).
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
