Forum Discussion
TMcGov_92811
Nimbostratus
Dec 08, 2008iRule to log SSL failures due to weak encryption
I have implemented the following Ciper in an SSL profile per F5 support to prevent SSLv2 or weak encryption schemes from connecting.
ALL:!NULL:!ADH:!LOW:!EXP:RC4+RSA:!SSLv2:+HIGH:+MEDIU...
hoolio
Cirrostratus
Dec 08, 2008To add to Denny's suggestion, you could set no restrictions on the client SSL profile, but then check the cipher bits and/or name in an iRule in HTTP_REQUEST. If the client's SSL spec is too low, you could send back a response or redirect. Here are a couple of related posts:
HTTPS Redirects (Click here)
Identify Client Cipher Strength (Click here)
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
