Forum Discussion
ringoseagull_77
Nimbostratus
Aug 17, 2010TLS Renegotiation Extension warning after upgrade to 10.1
Since upgrading a pair of 1600s from 9.4.7 to 10.1 we are getting TLS Renegotiation Extension warnings on https pages.
Is this a known problem (I can't see anything from a search) or is it that we are only now getting reports of an already present issue since upgrading?
We are also getting warnings about mixed encrypted and unencrypted content on https pages since the upgrade, which I'm certain would have been there before but we weren't getting the notifications.
- Chris_Miller
Altostratus
Have you validated your SSL VS configuration? The encrypted and unencrypted content error is always an interesting one. - ringoseagull_77
Nimbostratus
How would I do that? BTW no VS config or web site code has changed. I have renewed a couple of SSL certs and updated the relevant client SSL profiles to get rid of some chaining issues, but they're OK now. - Chris_Miller
Altostratus
Posted By ringoseagull on 08/17/2010 07:15 AM - hoolio
Cirrostratus
I think it was in 10.1 that a new client SSL option for enabling/disabling SSL renegotation was added. It should be set to disabled by default. You'll see a warning in /var/log/ltm when LTM requests/requires a client cert (based on a client SSL profile client cert setting or an iRule that calls SSL::renegotiate). If you don't enable SSL renegotiation on the client SSL profile, LTM will not renegotiate the SSL handshake. - ringoseagull_77
Nimbostratus
Yes, no boxes ticked in the client-ssl profile.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects