Forum Discussion
The SSL/TLS service uses Diffie-Hellman groups with insufficient strength (key size < 2048).
We have an issue with Diffie Helman Key after auto scan , how we can increase the Diffie helman Key to 2048
1 Reply
According to K89130356 , all of BIG-IP current versions use only 1024-bit group for DH/DHE ciphers. F5 does not have support for 2048-bits yet implemented at the time of creation of this article. There is an internal RFE opened for this feature.
You can tune your cipher list to remove support for DH and DHE protocols for key exchange, so that only Elliptic Curve ECDH/ECDHE suites will be negotiated in SSL handshake.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com