Forum Discussion
Example cipher suite needed...
I am running a box in our lab that is running 11.5.3. We have some very old Vista clients that need to access to two SSL VIPs. I need to use a cipher string that will support these ciphers below. I assume it will require use of the COMPAT stack.
TLS_RSA_WITH_AES_128_CBC_SHA TLS_RSA_WITH_AES_256_CBC_SHA TLS_RSA_WITH_RC4_128_SHA
Can some provide an example of a cipher string that will support these AES_128 and RC4 ciphers? I know this opens me up to vulnerabilities but I have no choice.
Thank you,
1 Reply
- Hannes_Rapp
Nimbostratus
I don't think you will need RC4. If you can test, give a try to
ALL:!EXPORT:!RC4:!DES:!ADH:!EDH:!SSLv3-This SSL/TLS config also complies with PCI DSS 3.0 (Enforced till the end of June 2016)
Although the string above qualifies for grade A in Qualys SSL labs, it's not perfect from a security standpoint. Windows Vista and XP clients on IE8 and newer can connect using TLS1.0 in combination with CBC.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com