For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Prasad4u's avatar
Prasad4u
Icon for Nimbostratus rankNimbostratus
Jan 08, 2021

Disable Weak Ciphers

Team,

 

I have tried disabling the weak ciphers using the Cipher.

 

Cipher Code : ECDHE+SHA256:HIGH:!SSLv3:!RSA:!RC4:!EXP:!LOW:!ADH:!DHE:!DES:!3DES:!TLSv1:!TLSv1_1:TLSv1_2

 

But Still, I can see few weak Ciphers in Ssllabs.com :

 

 

 

Cipher Suites# TLS 1.2 (suites in server-preferred order) 

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 128

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 256

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 256

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 128

 

1 Reply

  • Hi Prasad4u,

     

    Try to add !AES on you Cipher Code :

    ECDHE+SHA256:HIGH:!SSLv3:!RSA:!RC4:!EXP:!LOW:!ADH:!DHE:!DES:!3DES:!TLSv1:!TLSv1_1:TLSv1_2:!AES

    Regards