Forum Discussion
Open SSL error on ltm logs since v11 upgrade
We had the same problem at my office and it turns out that it was a Cipher issue with the HTTPS monitor. As part of web server hardening, everything but TLS1.2 was disabled on the web servers. The HTTPS monitor did have "DEFAULT:+SHA:+3DES:+kEDH" in the ciphers list and the 'DEFAULT' group does also include TLSv1.2 cipher suites but somehow this was causing problems.
I changed the cipher list to TLSv1_2+AES and this immediately fixed the problem - though it did create other problems as I did have a pool where some servers were hardened while others weren't. Adding this cipher suites caused the pool members pointing to the unhardened servers to go down.
In the end I couldn't find a compromise so I just put it to "tcp". Not the best solution but I need to get the server and application guys to fix it on the servers.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com