Forum Discussion
Enable SSLv3 for VIP on 11.5.1 HF7
The absolute easiest option is to modify the Ciphers option in the client SSL profile. SSLv3 is still supported in the NATIVE stack but was removed from the DEFAULT stack (a subset of NATIVE).
DEFAULT:SSLv3
But of course keep in mind that SSLv3 has recently been shown to have some pretty severe vulnerabilities and best practice is to avoid it if at all possible. At the very least also remove support for MD5 and DES-CBC-SHA, and potentially RC4:
DEFAULT:SSLv3:!MD5:!DES-CBC-SHA:!RC4
You can validate this list from the command line with the tmm --clientciphers tool:
tmm --clientciphers 'DEFAULT:SSLv3:!MD5:!DES-CBC-SHA:!RC4'
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com