Forum Discussion
Force Client-SSL Profile to X25519, Instead of Post-Quantum Cryptography
Hello Jeff_Granieri ,
Thank you for your concise reply. I implemented the instruction as directed. However, i noticed the client sent in X25519MLKEM,alongside X25519, that the F5 is supposed to only accept. That means, irrespective of whatever is done on F5, as long as the client browsers sends both key shares together, the F5 will accept it. Is there a way to force the Client to only send X25519, and probably force a HelloRetryRequest or something if it sends both. The problem is that with large ClientHello's, middleware boxes (that do DPI) are unable to cope with the sizes and then have to fragment traffic.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com