Forum Discussion
Disabling SSLv3 for Configuration Utility.
I tried to follow the instructions in SOL15702: SSLv3 vulnerability CVE-2014-3566 to disable SSLv3 for the Configuration Utility (BIG-IP v11.6.0).
Changing, i.e. removing SSLv3, by appending ":!SSLv3" or ":-SSLv3" to the ciphersuite led to my Firefox (v33) giving the following error:
"An error occurred during a connection to example.com. Cannot communicate securely with peer: no common encryption algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
and I could no longer connect to the CU. I have since reversed the change.
After looking into "/etc/httpd/conf.d/ssl.conf", I have found that it seems that what should be changed is "SSLProtocol" rather than "SSLCipherSuite".
2 Replies
- JG
Cumulonimbus
I have just seen this one: CVE-2014-3566: Removing SSLv3 from BIG-IP, which is right!
- JG
Cumulonimbus
I have found that SOL15702 has since been updated with correct information.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com