SSL Labs Best Case Grades for Older TMOS Versions
Aspiring for that A+ rating on Qualys SSL Labs? F5er Brandon Frelich went to work to determine the best case scenarios for older versions of TMOS. Quite an engaging project, hopefully you enjoy readi...
Published Mar 16, 2016
Version 1.0JRahm
Admin
Joined January 20, 2005
JRahm
Admin
Joined January 20, 2005
Simon_Waters_13
Mar 17, 2016Cirrostratus
I agree Brian, it isn't clear 4096-bits keys are worth it, but hey it is nice to have one aspect of the F5 config score better than F5's ;)
My paranoia is typical security paranoia (My predecessor in this role took part in the blacknet PGP key attack, and now he has all of facebook's resources at his disposal.....), plus demanding clients. For the service we put 4096-bit keys they already have PFS with common browsers, and have disabled DHE, and generally trying to stay ahead of the TLS issues. So when it comes to generate a key I use the longest I can. The hardware TLS termination is not currently anywhere near being the bottleneck, so the practical cost of longer keys is low unless traffic ramps up enormously. 2048 is now the recommended minimum length from NIST.