Forum Discussion
Remove TLS_RSA for PFS?
If you are running 11.6.2 HF1, you have already mitigated ROBOT even if you continue to use RSA key Exchange.
K21905460: BIG-IP SSL vulnerability (ROBOT) CVE-2017-6168
Please be aware of the note in K21905460
Note: Fixed BIG-IP versions do not disable RSA key exchange, they eliminate the existing code flaw in our implementation of RSA key exchange. Due to influences outside the control of the BIG-IP system, some SSL rating sites and scanners may falsely report that fixed versions are vulnerable to CVE-2017-6168. In these instances you may want to contact the scanner vendor to report the false positive result.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com