Forum Discussion
Exact syntax for SSL ciphers
The best thing to do - is view the ciphers that are currently in use via CLI.
How its displayed in the CLI (Bash) is how it should be put into the Client SSL Profile (I'm assuming that's where you want to disable them)
Alternatively the Client SSL profile also gives you options to do things the easy way like "Disable all SSL Ciphers" under the options section...
- Alin_Olar_24603Feb 13, 2017Nimbostratus
The Problem is i want to add ciphers , not remove them. Hence the issue with knowing the syntax.
- IainThomson85_1Feb 13, 2017Cumulonimbus
What Cipher do you want to use ? Ciphers are included in the version of OpenSSL that the BigIP is running.
- Alin_Olar_24603Feb 13, 2017Nimbostratus
This is what the request looks like :
SSLCipherSuite EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
SSLProtocol -ALL +TLSv1.1 +TLSv1.2
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com