Forum Discussion
TLS 1.2 fail connetcion
Hi
when working with IE 10 that work with TLS 1.2 we fail connect F5 VIP (version-BIG-IP 11.1.0 Build 2185.0 Hotfix HF4).when looking in trace we see that after certificate (from server) their is no continiuation and the browser display message error. Cipher used TLS_RSA_WITH_RC4_128_SHA. please advise
14 Replies
- What_Lies_Bene1
Cirrostratus
What is the browser error message please? What is the last SSL packet/message you see in the trace?
- Yalkrif_99781
Nimbostratus
browser error "page cant be display " and the last message from server is certificate, server hello done
- amolari
Cirrostratus
do you have this issue with Network Access? Be aware that TLS 1.2 for NA is supported from v11.2.1 HF6 on. Here from the RN 412084 The network access client now supports TLS1.2.
- What_Lies_Bene1
Cirrostratus
OK, is the ClientSSL profile configured to require a client certificate perhaps?
- Yalkrif_99781
Nimbostratus
we are using LTM. and we dont configure client certificate perhaps
- What_Lies_Bene1
Cirrostratus
OK, any server-side SSL occuring? You're use of the word 'server' suggests maybe there is. Did you take the capture client-side or server-side?
- Yalkrif_99781
Nimbostratus
from server i mean F5 VIP , i took the trace on client side.no server side SSL . when connecting TLS 1.0/SSLv3 everything works fine. thanks
- What_Lies_Bene1
Cirrostratus
OK, understood, thanks. So, is the certificate signed with MD5 by any chance? There seems to be an issue with this and TLS 1.2.
Still, the odd thing is that SSL seems to be working and negotiated just fine, you just don't get any HTTP passing once the channel has been established. Do you never see data from the client after the ServerHelloDone? If not, that suggests the client is at fault.
Seeing any errors in the logs? You could up the SSL logging to debug via System > Logs > Options or tmsh: 'modify sys db log.ssl.level value debug'. Obviously don't do this on a production VS.
- Yalkrif_99781
Nimbostratus
i turned debug on and i see only the below
tmm info tmm[7105]: 01260013:6: SSL Handshake failed for TCP from
- What_Lies_Bene1
Cirrostratus
Sorry, did you cut off the rest of the message?
- Yalkrif_99781
Nimbostratus
no , this is the whole message from ltm log , its weird to me also that we don't see debug( i enable it from GUI)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com