Forum Discussion
Moinul_Rony
Altostratus
Sep 04, 2014How to disable CIPHER for and Disable TCP time stamp on F5 ?
Hi,
We have just being chased by PCI Compliance about having vulnerabily that detected WEAK CIPHER support and TCP Timestamp being turned ON.
--Report say our application:
Negotiated with the fol...
nitass
Employee
Sep 04, 2014i normally see people using cipher string from this sol if there is no special requirement.
sol13171: Configuring the cipher strength for SSL profiles (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/100/sol13171.html
for tcp timestamp, is it this one?
TCP timestamp response
http://www.rapid7.com/db/vulnerabilities/generic-tcp-timestamp
sol8072: Obtaining uptime information from TCP timestamps
http://support.f5.com/kb/en-us/solutions/public/8000/000/sol8072.html
- Moinul_RonySep 06, 2014
Altostratus
Thanks, on another point PCI scan pointed out absense of "Forward Secrecy with the reference browsers". Can this be implemented/enforced via F5? - nitassSep 06, 2014
Employee
dh is natively supported in 11.2.1 Diffie-Hellman SSL key exchange cipher The Diffie-Hellman SSL key exchange cipher, which provides perfect forward secrecy (PFS), is now included natively. This provides better performance for configurations using Diffie-Hellman, especially on physical platforms that have hardware SSL acceleration. Release Note: BIG-IP LTM and TMOS 11.2.1 http://support.f5.com/kb/en-us/products/big-ip_ltm/releasenotes/product/relnote-ltm-11-2-1.html - Moinul_RonySep 06, 2014
Altostratus
Unfortunately we are using 11.2.0. Any chance to enforce DH ? - nitassSep 06, 2014
Employee
dh is supported in compat ssl stack in 11.2.0. sol13163: SSL ciphers supported on BIG-IP platforms (11.x) http://support.f5.com/kb/en-us/solutions/public/13000/100/sol13163.html - Moinul_RonySep 07, 2014
Altostratus
sorry but enabling COMPAT cipher brought down the grading to F in SSLLABS. - nitassSep 07, 2014
Employee
you can list cipher using tmm --clientciphers command. tmm --clientciphers (cipher string)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects