Forum Discussion
SSL Key length changed after 11.6.0 upgrade
Hi, We recently upgraded from 11.4.1 to 11.6.0. Since then we have noticed an apparent drop in traffic in one of our monitoring tools, but this doesn't correlate to anywhere else.
After much digging around we have noticed that the majority of traffic is now using SHA256 ciphers, whereas all traffic was previously SHA128 encrypted.
We obviously need to work with our monitoring provider to upgrade their capabilities, but is there a way we can drop back down to SHA128, temporarily? I can't see any options under the SSH client profile.
Thanks,
Damian
1 Reply
- damian_19221
Nimbostratus
I've been digging around and found a matrix of all the supported versions of SSL for 11.x
Would updating my Cipher list in SSL Client profile as below work? This is just including the ciphers supported in 11.4. Again, this is temporarily until our monitoring provider can update their supported ciphers.
RC4-MD5:RC4-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA:DES-CBC-SHA:EXP1024-RC4-SHA:EXP1024-DES-CBC-SHA:EXP-RC4-MD5:EXP-DES-CBC-SHA:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:DHE-RSA-DES-CBC-SHA:DHE-RSA-DES-CBC3-SHA:AES128-SHA256:AES256-SHA256:ECDHE-RSA-AES128-CBC-SHA:ECDHE-RSA-AES256-CBC-SHA:ECDHE-RSA-DES-CBC3-SHA:!SSLv3https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13163.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com