Forum Discussion
Patrick_Chang_7
Apr 08, 2009Historic F5 Account
What is max length of SSL key we can use on LTM?
Can I use an SSL Cert with a 4096 bit long key? If not, what needs to be adjusted to make this work? Thanks.
2 Replies
- Steve_87232
Nimbostratus
Anyone have an update on this? Does 10.x support 4096? I can't seem to verify the answer. - hoolio
Cirrostratus
Hi Steve,
Apparently for client or server SSL, you can use certs/keys larger than 2048 bits if you use software SSL decryption:
From case C564817:
You can specify a cipher string of "DEFAULT:!NATIVE" and the "!NATIVE" will rule out using the acceleration card and just use software.
This is also noted in SOL10580:
SOL10580: The SSL key size is limited when using hardware acceleration
https://support.f5.com/kb/en-us/solutions/public/10000/500/sol10580.html
If you open a case with F5 you can ask to have your request added to CR124105.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects