Forum Discussion
Host is Vulnerable to Extended Master Secret TLS Extension (TLS triple handshake)
which tmos version are you using?
just to make sure, you seeing a difference between SSL enabled VIPs? not between a non SSL and a SSL enabled VIP?
as for you last question, yes the setting can only be changed from the CLI, but in general you dont want to change the setting, as it is a way to prevent to tls triple handshake.
assuming this comes from qualys this thread is interesting to read:
https://qualys-secure.force.com/discussions/s/question/0D52L00004TnvDPSAZ/regarding-rfc-7627-on-transport-layer-security-tls-session-hash-and-extended-master-secret-extension-will-become-a-mandatory-tls-extension
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
