Forum Discussion
we have to recompile openssl on F5
hello By default OpenSSL uses a custom build system to configure the library. But we face a issue with client , for some reason we cannot change properties of TLS client (carte CPS firmware )
In orde to solve the issue we have to re-compile openssl with the option -DOPENSSL_NO_SHA512 .This option not allow the client to choose Sha512 with the server for the TLS connection.
But we don't understand how to perform this action. Could you please help us ?
2 Replies
- DevBabu
Cirrus
Where do you want to disable SHA512, between Client and VIP or VIP and Server. Is ssl offloaded on F5.
- jbrunetext_2297
Nimbostratus
We use the TMOS 10.2.4 plateform. The issue is on server F5, we haven't set the ssl offloaded on F5, we use the basic configuration however the TLS/SSL protocol always choose the best protocol sign hash "SHA512" but our SD card is not compatible with SHA512. We need to disabled the SHA512 in order to connect the client browser with SDcard on F5.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com