Forum Discussion
Is !SSLv3 the same as No SSLv3 ?
Hi everybody
I've some question about SSL profile.
Is !SSLv3 specify in cipher suite the same as "No SSLv3" option in SSL option?
Thank you very much
- Rupert_Connell_Nimbostratus
No it is not!
!SSLv3 hard disables the SSLv3 ciphers. No SSLv3 disables the SSLv3 protocol.
If you set !SSLv3, but not No SSLv3, the client may negotiate SSLv3 as protocol, then not be able to use any ciphers, since you have disabled them!
See here for reference: Cipher Suite Practices and Pitfalls
this one deserves a few upvotes to make sure it is on top.
- Rupert_ConnellAltostratus
No it is not!
!SSLv3 hard disables the SSLv3 ciphers. No SSLv3 disables the SSLv3 protocol.
If you set !SSLv3, but not No SSLv3, the client may negotiate SSLv3 as protocol, then not be able to use any ciphers, since you have disabled them!
See here for reference: Cipher Suite Practices and Pitfalls
this one deserves a few upvotes to make sure it is on top.
- Faruk_AYDINNimbostratus
Yes, It is equivalent.
- Faruk_AYDINNimbostratus
use :
and also disable weak ciphers.ALL:!SSLv2!SSLv3
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com