Forum Discussion
Need help to set Cipher
Hi
We are running on Ver 10.2.4 and have below cipher string on our SSL profile.
ALL:!SSLv3:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:HIGH:MEDIUM:RSA:RC4:@SPEED
We want to disable RC4 and enable AES but keeping TLS1.0 enabled. But when I use below Cipher string to accomplish this
ALL:!SSLv3:!RC4:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:TLSv1:HIGH:MEDIUM:RSA+AES:@SPEED
It still shows RC4 enabled and the rating is C on SSL labs.
Please suggest correct string to do this
3 Replies
- jcline
Nimbostratus
I use this string on my profiles. It gets me a score of 93% using my calomel plugin and a B from SSLlabs. I haven't had any problems with compatibility.
DHE+HIGH:TLSv1_2:TLSv1_1:!SSLv3:TLSv1:!RC4:!MD5:!ADH:!LOW:!EXPORT:!DES:@SPEED
- jcline
Nimbostratus
We are on version 11.6 but I'm pretty sure that we brought that cipher string up from version 10.
- Kevin_Stewart
Employee
The best way to test for a given set of ciphers, based on your cipher string, is with the tmm --clientciphers command:
tmm --clientciphers 'ALL:!SSLv3:!RC4:!SSLv2:!aDH:!LOW:!EXPORT:!NULL:!MD5:TLSv1:HIGH:MEDIUM:RSA+AES:@SPEED'This will dump all of the ciphers that meet the above criteria. I'm pretty sure the above string doesn't produce RC4 ciphers, but I don't have a 10.x box in front of me to test.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com