Forum Discussion
SSL/TLS use of weak RC4 cipher
Can some one help me please to correct this vulnérablitty i try to the changing cipher string for the SSL profile associeted with VS in my asm version 11.4.1 hostfix4 with :!SSLv3:RC4-SHA . but still vulnerability persist
Thanks
4 Replies
- nathe
Cirrocumulus
Does:!SSLv3:!RC4 help?
N
- afedden_1985
Cirrus
if YOUR ASKING ABOUT THE MANAGEMENT INTERFACE THIS MIGHT WORK AND I USE IT ON MY LTMS. this string seems to be good and only supports TLS1.2 ciphers .
modify sys httpd ssl-ciphersuite NONE:DHE-RSA-AES256-SHA:AES256-SHA Save sys config
- Hannes_Rapp
Nimbostratus
- What this means? Do not permit a combination of SSLv3 and RC4-SHA cipher suite. This does not tell that RC4-SHA is prohibited for TLS1.0, TLS1.1 or TLS1.2. That's why your issue prevails.!SSLv3:RC4-SHA - Max_Q_factor
Cirrocumulus
Maybe you can review this article that talks about what an affective cipher list looks like -
Or this solution article on how to view the affective cipher suite lists on the BIG-IP:
SOL15194: Overview of the BIG-IP SSL/TLS cipher suiteOr this article:
SOL13171: Configuring the cipher strength for SSL profiles (11.x)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com