Forum Discussion

Abi80_167352's avatar
Abi80_167352
Icon for Nimbostratus rankNimbostratus
Oct 21, 2014

how to disable SSLV3

whats teh syntax i need to add in client profile to disable SSLV3 cipher

 

4 Replies

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    The following post has all the info and links you need to address POODLE on your BIGIP: https://devcentral.f5.com/articles/cve-2014-3566-removing-sslv3-from-big-ip

    Please read this SOL for F5's procedure on modifying your cipher lists: https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13171.htmlblockspecific

    If you are using the configuration utility (GUI), append the following to the cipher list of the custom client-ssl or server-ssl profile (never alter F5 default profiles): !SSLv3. An example would be "DEFAULT:!SSLv3". The CLI command would be something like the following, but you will want to use the profile's current cipher list and append :!SSLv3, otherwise you will replace it entirely with what is specified in the command:

    tmsh modify ltm profile client-ssl (profile-name) ciphers DEFAULT:!SSLv3

  • Thank you alll

     

    Once i have SSLV3 disabled , caan anyone help with the syntax or command i can run on F5 to verify its now running TLS1 in cypher suite

     

  • Don't forget monitors have a separate configuration. They are run out of OpenSSL which is separate from payload settings. You can run openssl ciphers -v 'ALL:!SSLv2' to see if TLS is supported for monitors in the version you are running.