For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

damian_19221's avatar
damian_19221
Icon for Nimbostratus rankNimbostratus
Aug 14, 2015

SSL Key length changed after 11.6.0 upgrade

Hi, We recently upgraded from 11.4.1 to 11.6.0. Since then we have noticed an apparent drop in traffic in one of our monitoring tools, but this doesn't correlate to anywhere else.

 

After much digging around we have noticed that the majority of traffic is now using SHA256 ciphers, whereas all traffic was previously SHA128 encrypted.

 

We obviously need to work with our monitoring provider to upgrade their capabilities, but is there a way we can drop back down to SHA128, temporarily? I can't see any options under the SSH client profile.

 

Thanks,

 

Damian

 

1 Reply

  • I've been digging around and found a matrix of all the supported versions of SSL for 11.x

    Would updating my Cipher list in SSL Client profile as below work? This is just including the ciphers supported in 11.4. Again, this is temporarily until our monitoring provider can update their supported ciphers.

    RC4-MD5:RC4-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA:DES-CBC-SHA:EXP1024-RC4-SHA:EXP1024-DES-CBC-SHA:EXP-RC4-MD5:EXP-DES-CBC-SHA:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:DHE-RSA-DES-CBC-SHA:DHE-RSA-DES-CBC3-SHA:AES128-SHA256:AES256-SHA256:ECDHE-RSA-AES128-CBC-SHA:ECDHE-RSA-AES256-CBC-SHA:ECDHE-RSA-DES-CBC3-SHA:!SSLv3
    

    https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13163.html