Forum Discussion
TLS record layer version
TLS record layer version is not present in client SSL profile. Please check the last part of the doc, where it mentions beginning v 12.1.0, TLS record layer version is used TLS1.0 unless db value is disabled.
Beginning in BIG-IP 11.5.4 HF2 for the BIG-IP 11.5.x branch and BIG-IP 12.1.0 HF1 and later, the ssl.outerrecordtls1_0 database variable is introduced. Prior to this database variable, the version present in the ClientHello and the version present in the outer record match. With the introduction of this database variable, which is enabled by default, the version present in the outer record is TLS 1.0, regardless of the version in the ClientHello. To verify the value of ssl.outerrecordtls1_0, perform the following procedure:
Thanks for the information Sanjay...
Does this means F5 will accept any version of TLS record layer coming from the client.
Actually, we need a confirmation that our device will accept any version of TLS record layer coming from the client. And how do we confirm this?
Regards
- spalandeApr 21, 2021Nacreous
Please note, ssl.outerrecordtls1_0 this variable is for serverside TLS session. i.e. from F5 to the server where F5 initiates CLIENT HELLO towards the server.
For client side TLS session, as mentioned earlier there is no TLS record layer version option. BIGIP accepts all TLS record layer version, the one which matters is CLIENT HELLO version coming from the client. If that's not matching what is allowed on client ssl profile, BIGIP would reset the connection.
Are you having any issue in particular with this?
- ShirazApr 21, 2021Altostratus
Thanks for your response. Can we have any reference article stating that BIG-IP accepts all TLS record layer versions? Need to provide it to one of the client....
Thanks again for your support...
- spalandeApr 21, 2021Nacreous
Sorry don't have it. I'm telling it from my experience of working with BIGIP quite few years now :)
If you are looking for an official doc, you can log a general information support case with F5 and they can provide the link.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com