Forum Discussion
Amit585731
Nimbostratus
Apr 21, 2016Regarding signature algorithm
Hi All,
We are seeing issue where when we are sending TLSv1.2 to server (i.e. serverssl profile present) it is dropping the connection. When I am sending TLSv1 then connection is successful. My ...
Minn_62043
Cirrostratus
Apr 25, 2016According to RFC5246, signature_algorithm is not strictly required. Anyway, from the screenshot I couldn't see the Data part in "signature_algorithm". There is 32 byte Data in signature_algorithm. If you click that row, you will see some details, and they should describe the list of hash and signature algorithms supported by F5. You can verify if the list contains the pair with SHA256.
What is really the server's requirement? Client must use SHA-2 and include the ability in signature_algorithm extension?
- Amit585731Apr 25, 2016
Nimbostratus
Minn, Since by adding signature_algorithm it starts to work so I think that is the issue here. Any suggestion hot to enable this on LB? - Amit585731May 18, 2016
Nimbostratus
Hi Minn, sorry for late comment. Yeah I can see 32 byte data field and it shows sha2 n sha1 as well. Can you please suggest how this can be enabled on 11.6 and 11.4. From some forum I found that this is enabled by default in 11.6 and to enable on 11.4 we need to work with irule. But on none of code I am unable to figure out how to proceed. Thanks
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects