Forum Discussion
Hamish
Cirrocumulus
Nov 05, 2009SSL Vulnerability
Does anyone know if F5's with SSL Offload are vulnerable to the plain text insertion vulnerability that's been reported today?
Details are vague (As you'd expect) but IIUC it may be only client cert authentication that's vulnerable (Or not).
Anyone got any details?
H
- hoolio
Cirrostratus
hi Hamish, - Hamish
Cirrocumulus
- Hamish
Cirrocumulus
Oh. I also have a case open with F5... They're asking ENE... - Hamish
Cirrocumulus
I have an answer from F5. - hoolio
Cirrostratus
Hi Hamish, - Lupo_38935
Nimbostratus
Hamish: As outlined in the "Renegotiating TLS" paper, insertion is indeed possible even without the use of client certificat authentication. The real impact then depends on the application.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects