Forum Discussion
Disabling Ciphers
- May 18, 2018
@Rob, Do you want to disable only Weak cipher, which you have pasted in Question section. Let us know.
@Rob, Do you want to disable only Weak cipher, which you have pasted in Question section. Let us know.
- Rob_HigginbothaMay 18, 2018Nimbostratus
I want to disable only the ciphers I noted as weak
Thanks
- Samir_Jha_52506May 19, 2018Noctilucent
Disable below cipher in-order to eliminate weak cipher list. I have tested in v12 and all weak cipher gone. Suggest you to test in LAB environment and share feedback. Most important thing, don't play with default
profile which has pointed by @SBlakelyclient-ssl
Find the weak cipher list as per above question .
AES256-SHA256 AES128-SHA256 AES256-SHA AES128-SHA DES-CBC3-SHA
TLS 1.1 (Weak suites in server-preferred order)
AES256-SHA AES128-SHA DES-CBC3-SHA
TLS 1.0 (Weak suites in server-preferred order)
AES256-SHA AES128-SHA DES-CBC3-SHA
- Rob_HigginbothaMay 31, 2018Nimbostratus
My Apologies for being dumb - So, I copy the above list in the "Ciphers" section in the clientssl profile that I created? Anything else? What am I missing?
Thank you for your help
When I try this I'm getting an error
01070312:3: Invalid keyword ' aes256-sha256' in ciphers list for profile /Common/clientssl-test-cyphers
Cipher List to insert.
AES256-SHA256: AES128-SHA256: AES256-SHA: AES128-SHA: DES-CBC3-SHA: AES256-SHA: AES128-SHA: DES-CBC3-SHA: AES256-SHA: AES128-SHA: DES-CBC3-SHA:
- Samir_Jha_52506May 31, 2018Noctilucent
Try this
DEFAULT:ECDHE:!RSA:!DHE:!3DES
- Rob_HigginbothaJun 01, 2018Nimbostratus
Thank you - You are a genius!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com