Forum Discussion
daveferrier_202
Nimbostratus
Feb 25, 2019how to prioritize cipher suites
I am running version LTM BIGIP 12.1.3.5 and confused as to how to prioritize cipher suites.
I am using this cipher string on some client and server side ssl profiles. DEFAULT:@STRENGTH:!3DES:!EX...
wlopez
Cirrocumulus
Feb 25, 2019You can test your cipher string using the following commands from bash:
tmm --clientciphers 'YOUR CLIENT SSL CIPHER STRING'
tmm --serverciphers 'YOUR SERVER SSL CIPHER STRING'
Exammple:
This will give you the default client ssl ciphers for the version your running:
tmm --clientciphers 'DEFAULT'
With it you can see what's active by default on your version, and start working from there.
To view your current setup:
tmm --clientciphers 'DEFAULT:@STRENGTH:!3DES:!EXPORT:!EXP:!MD5:!RC4'
My recommendation based on your version, to comply with just about every regulation out there would be:
tmm --clientciphers 'ECDHE:DEFAULT:!DHE:!3DES:!TLSv1:@STRENGTH'Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects