Forum Discussion
TLS record layer version
Dears,
As mentioned in the article https://support.f5.com/csp/article/K53037818 .. TLS servers compliant with the TLS1.2 specification must accept any value as the record layer version number for ClientHello.
It also mentioned that "When you encounter issues with SSL handshakes failing due to the record layer version in the ClientHello message, you should first review the configuration on the TLS server."
As of now, we would like to know where can we see the configuration of TLS record layer version in F5 Client SSL Profile.
Thanks in Advance.
Mohammed Shiraz
- spalandeNacreous
TLS record layer version is not present in client SSL profile. Please check the last part of the doc, where it mentions beginning v 12.1.0, TLS record layer version is used TLS1.0 unless db value is disabled.
Beginning in BIG-IP 11.5.4 HF2 for the BIG-IP 11.5.x branch and BIG-IP 12.1.0 HF1 and later, the ssl.outerrecordtls1_0 database variable is introduced. Prior to this database variable, the version present in the ClientHello and the version present in the outer record match. With the introduction of this database variable, which is enabled by default, the version present in the outer record is TLS 1.0, regardless of the version in the ClientHello. To verify the value of ssl.outerrecordtls1_0, perform the following procedure:
- ShirazAltostratus
Thanks for the information Sanjay...
Does this means F5 will accept any version of TLS record layer coming from the client.
Actually, we need a confirmation that our device will accept any version of TLS record layer coming from the client. And how do we confirm this?
Regards
- spalandeNacreous
Sorry don't have it. I'm telling it from my experience of working with BIGIP quite few years now :)
If you are looking for an official doc, you can log a general information support case with F5 and they can provide the link.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com