Forum Discussion
dmezack_359144
Nimbostratus
Apr 19, 2018Weak DH Keys solved by !DHE?
Adding !DHE to the below F5 SSL profile cipher string (11.X & 12.X) resolved the below SSL Labs issue.
DEFAULT:!LOW:!RC4:!MD5:!SHA1:!ADH:!DHE:!DES:!3DES:!EXP
Resolved: Weak Diffie-Hellman (...
dmezack_359144
Nimbostratus
Apr 19, 2018According to answers on [What is ECDHE-RSA](o https://security.stackexchange.com/questions/14731/what-is-ecdhe-rsa):
- “ECDHE suites use elliptic curve diffie-hellman key exchange, where DHE suites use normal diffie-hellman. This exchange is signed with RSA, in the same way in both cases”
- "ECDHE is also resistant to recently published attacks against traditional DH cipher-suites in TLS"
It would be valuable to have F5 confirm if !DHE sufficiently addresses this risk by using elliptic curfe diffie-hellman key exchange with lower "EC" key sizes required.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects