For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

swapnil_89332's avatar
swapnil_89332
Icon for Nimbostratus rankNimbostratus
Sep 22, 2015

Need help to set Cipher

Hi

 

We are running on Ver 10.2.4 and have below cipher string on our SSL profile.

 

ALL:!SSLv3:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:HIGH:MEDIUM:RSA:RC4:@SPEED

 

We want to disable RC4 and enable AES but keeping TLS1.0 enabled. But when I use below Cipher string to accomplish this

 

ALL:!SSLv3:!RC4:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:TLSv1:HIGH:MEDIUM:RSA+AES:@SPEED

 

It still shows RC4 enabled and the rating is C on SSL labs.

 

Please suggest correct string to do this

 

3 Replies

  • jcline's avatar
    jcline
    Icon for Nimbostratus rankNimbostratus

    I use this string on my profiles. It gets me a score of 93% using my calomel plugin and a B from SSLlabs. I haven't had any problems with compatibility.

     

    DHE+HIGH:TLSv1_2:TLSv1_1:!SSLv3:TLSv1:!RC4:!MD5:!ADH:!LOW:!EXPORT:!DES:@SPEED

     

  • jcline's avatar
    jcline
    Icon for Nimbostratus rankNimbostratus

    We are on version 11.6 but I'm pretty sure that we brought that cipher string up from version 10.

     

  • The best way to test for a given set of ciphers, based on your cipher string, is with the tmm --clientciphers command:

    tmm --clientciphers 'ALL:!SSLv3:!RC4:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:TLSv1:HIGH:MEDIUM:RSA+AES:@SPEED'
    

    This will dump all of the ciphers that meet the above criteria. I'm pretty sure the above string doesn't produce RC4 ciphers, but I don't have a 10.x box in front of me to test.