Forum Discussion
Proxy SSL Cipher Suite
Hi,
I've been trying to make proxy ssl work from many days after a long research. I want to know if proxy ssl requires specific ciphers to be used? I am using DEFAULT for both client and server ssl profile. I am getting an error which could be related to ciphers.
Regards
21 Replies
Hello
What is the error message ?
AFAIK, the proxy ssl feature support only RSA.
No support for DH, EDH and ECC
- Nuruddin_Ahmed_
Cirrostratus
Hi, What would be the appropriate line which i can write instead of DEFAULT in cipher suite filed for RSA? The error message seen on the explorer window, i still have not run the packet capture. I would do further troubleshooting once the cipher suits are correct. I am newbie :( - Unfortunately, as there is no ssl bridging nor offloading configured on the bigip, ciphers are negociated between the browser and the backend server
- Nuruddin_Ahmed_
Cirrostratus
just wanted to know one thing. in the server ssl and client ssl profile, we would be providing on the Server certification. I have a single certificate for web server authentication as well as for client authentication. Do i need to get a certificate for server authentication only which would work?
- Yann_Desmarest_
Nacreous
Hello
What is the error message ?
AFAIK, the proxy ssl feature support only RSA.
No support for DH, EDH and ECC
- Nuruddin_Ahmed_
Cirrostratus
Hi, What would be the appropriate line which i can write instead of DEFAULT in cipher suite filed for RSA? The error message seen on the explorer window, i still have not run the packet capture. I would do further troubleshooting once the cipher suits are correct. I am newbie :( - Yann_Desmarest_
Nacreous
Unfortunately, as there is no ssl bridging nor offloading configured on the bigip, ciphers are negociated between the browser and the backend server - Nuruddin_Ahmed_
Cirrostratus
just wanted to know one thing. in the server ssl and client ssl profile, we would be providing on the Server certification. I have a single certificate for web server authentication as well as for client authentication. Do i need to get a certificate for server authentication only which would work?
- Nuruddin_Ahmed_
Cirrostratus
Thanks yann, you have been of great help. From the ssldump, i can see that some of the machines are matching ciphers, looks like it should be working for them but for my test machines i get a TCP reset straightway that could be because of cipher suit mismatch. Below are some of the logs -
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com