Forum Discussion
Moinul_Rony
Altostratus
Jan 07, 2015Removing Poodle TLS padding vulnerability returns RC4 warning
Hi,
We are running F5 LTM version 11.2. Recently we disabled the RC4 weak CIPHER to remove the Minimal warning from our PCI scan.
But due to the recent arrival of Poodle TLS vulnarability ...
boneyard
MVP
Jan 07, 2015Alex is correct, the solution for POODLE TLS and some other attacks is to enable only RC4. but on the other side RC4 is considered unsafe itself and will probably to publicly announced to be disabled at some time in future.
so the best fix for POODLE TLS remains the hotfix version.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects