Forum Discussion
SSL Cert verification by https://www.ssllabs.com gets B grade
SSL cert verification says : 1) The server's Diffie-Hellman parameter is too small. Non-compliant with NIST, HIPAA and PCI DSS How do I fix this. Any recomendations. The Diffie-Hellman parameter's size is only 1024 bits . A longer one must be generated to prevent Logjam vulnerability. 2) This server's certificate chain is incomplete. How do i fix this in F5 LTM . I am using SSL termination Client side. Any pointer is appreicated. 3) I am using default Cipher on F5 client sll profile. The server supports cipher suites that are not approved by NIST guidelines and HIPAA guidance.
8 Replies
- RaghavendraSY
Altostratus
Please update intermediate certificate too and then verify the status and you can also disable weaker ciphers in ssl client profile. Which version you are running in f5?
- SP_266134
Nimbostratus
I am not sure where to get the is intermediate certificate. Where do i need to import the intermediate certificate. I am using f5 13.0 VE.
Intermediate Certificates and Root Certificates are provided by your certificate authority (CA).
- RaghavendraSY_7
Cumulonimbus
Please update intermediate certificate too and then verify the status and you can also disable weaker ciphers in ssl client profile. Which version you are running in f5?
- SP_266134
Nimbostratus
I am not sure where to get the is intermediate certificate. Where do i need to import the intermediate certificate. I am using f5 13.0 VE.
Intermediate Certificates and Root Certificates are provided by your certificate authority (CA).
- RaghavendraSY
Altostratus
When you receive certificates from third-party vendor they provide 4 certificates. 1. Website certificate 2. Trusted certificate authority v5 3. usertrustAdd certificate 4. Add trust certificate
You can bundle Addtrust and user trust certificate as intermediate and then import as intermediate certificate and then call in SSL client profile.
- RaghavendraSY
Altostratus
When you receive certificates from third-party vendor they provide 4 certificates. 1. Website certificate 2. Trusted certificate authority v5 3. usertrustAdd certificate 4. Add trust certificate
You can bundle Addtrust and user trust certificate as intermediate and then import as intermediate certificate and then call in SSL client profile.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com