Forum Discussion
Remove TLS_RSA for PFS?
If you are running 11.6.2 HF1, you have already mitigated ROBOT even if you continue to use RSA key Exchange.
K21905460: BIG-IP SSL vulnerability (ROBOT) CVE-2017-6168
Please be aware of the note in K21905460
Note: Fixed BIG-IP versions do not disable RSA key exchange, they eliminate the existing code flaw in our implementation of RSA key exchange. Due to influences outside the control of the BIG-IP system, some SSL rating sites and scanners may falsely report that fixed versions are vulnerable to CVE-2017-6168. In these instances you may want to contact the scanner vendor to report the false positive result.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
