Forum Discussion
Server SSL Profile
Can someone explain this in the server ssl profile properties. I thought that the BIG-IP was server cipher preference. So between the BIG-IP and server the BIG-IP is the client. But from the statement below this is saying the opposite. Please explain.
Cipher server preference: When the BIG-IP system chooses a cipher, this option uses the server's preferences instead of the client preferences. When this option is not set, the SSL server always follows the clients preferences. When this option is set, the SSLv3/TLSv1 server chooses by using its own preferences. For SSLv2, the server sends its list of preferences to the client, and the client always chooses the cipher.
- Kevin_K_51432Historic F5 Account
Greetings,
https://support.f5.com/csp/article/K12390
Hope this is helpful!
- SIP_354925Nimbostratus
Thanks for the response and explanation. Agreed. That article needs an update.
- Kevin_K_51432Historic F5 Account
Your welcome. I've requested an update for the article.
After digging in a bit more, I'd like to confirm that you were correct in your initial summary:
"I thought that the BIG-IP was server cipher preference"
So if this bug is fixed, either the option will be removed, or another possible option could be to move this into the enabled box of the SSL profile.
Kevin
- SIP_354925Nimbostratus
Thanks!!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com