For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

chipgwyn_178378's avatar
chipgwyn_178378
Icon for Nimbostratus rankNimbostratus
Nov 25, 2014

SOL10737 iRule Change from v10 to v11?

ltm on v10 had an irule of:

 

rule SOL10737_SSL_Renegotiation {
  when CLIENTSSL_HANDSHAKE priority 1 {
     APP-LOW-002: SSL/TLS Renegotiation Handshakes Man-In-The-Middle Plaintext DataInjection
    SSL::renegotiate disable
  }
}

same rule in v11 gives me:

 

    err tmm2[23569]: 01220001:3: TCL error: /BLUEpartition/SOL10737_SSL_Renegotiation  - command returned bad code: 24     while executing " APP-LOW-002: SSL/TLS Renegotiation Handshakes Man-In-The-Middle Plaintext Data Injection     SSL::renegotiate disable"

All the commands and such seem valid according to the docs. Granted I'm pretty new to iRules and such though.

 

2 Replies

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    based on the error message, it almost looks like the comment and ssl:renegotiate lines are being treated as one line. can you try putting a few extra carriage-returns between them and see if the error goes away?

     

  • Thanks for the recommendation Shaggy, that didn't seem to resolve it. I finally just removed the comment and it seems to not generate an error now.