Forum Discussion
qusai
Feb 27, 2022Nimbostratus
The SSL/TLS service uses Diffie-Hellman groups with insufficient strength (key size < 2048).
We have an issue with Diffie Helman Key after auto scan , how we can increase the Diffie helman Key to 2048
CA_Valli
Feb 28, 2022MVP
According to K89130356 , all of BIG-IP current versions use only 1024-bit group for DH/DHE ciphers. F5 does not have support for 2048-bits yet implemented at the time of creation of this article. There is an internal RFE opened for this feature.
You can tune your cipher list to remove support for DH and DHE protocols for key exchange, so that only Elliptic Curve ECDH/ECDHE suites will be negotiated in SSL handshake.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects