Forum Discussion
refra_151287
Jan 24, 2017Cirrus
SSL: Restrict Key Exchange Length
Hi,
any idea how to restrict Key exchange protocols that are based on DHE or RSA protocols with keys not less than 2048-bits in length?
IheartF5_45022
Nacreous
Unfortunately you can't - F5 only supports 1024 bits for DHE. In real-life terms this should be enough (unless the Russians are after you), however if scans are complaining then you'll need to disable DHE ciphers and use only ECDHE instead.
refra_151287
Jan 26, 2017Cirrus
Thanks a lot, how can I know the key length for the other algorithms?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects