# DES-CBC3-SHA listed as 192 bits but SSL Labs reports as 112 bit

**URL:** <https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748>\
**Category:** Technical Forums\
**Tags:** ciphers\
**Created:** [April 2, 2015, 1:19pm UTC](https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748 "2015-04-02T13:19:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![HTTP500\_195339](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@HTTP500\_195339](https://community.f5.com/u/HTTP500_195339)\
**Post date:** [April 2, 2015, 1:19pm UTC](https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748/1 "2015-04-02T13:19:17Z")

</div>

In the table [here](https://support.f5.com/kb/en-us/solutions/public/13000/100/sol13156.html) under the BIG-IP 11.5.0 - 11.5.2 section it lists the DES-CBC3-SHA ciphers as 192 bits.

However a SSL Labs scan will report the following:

TLS\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA (0xa)112 [bits]

I’m not a crypto-nerd but if I read [this explanation](http://kb.juniper.net/InfoCenter/index?page=content&id=KB29623&actp=RSS) correctly that particular cipher has an _ **effective security** _ of 112 bits but if the encryption is achieved by using 3 56 bit keys (3 X 56 = 168) why is F5 reporting 192 bits?

---

<div class="post-metadata">

**Author:** ![HTTP500\_195339](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@HTTP500\_195339](https://community.f5.com/u/HTTP500_195339)\
**Post date:** [April 9, 2015, 6:38pm UTC](https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748/2 "2015-04-09T18:38:03Z")

</div>

No one at F5 can answer this?

---

<div class="post-metadata">

**Author:** ![amolari](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@amolari](https://community.f5.com/u/amolari)\
**Post date:** [April 9, 2015, 8:04pm UTC](https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748/3 "2015-04-09T20:04:43Z")

</div>

there was a thread about that [here](https://devcentral.f5.com/questions/ssllabs-a-f5-ltm-114)

It seems to be a “bug”.. 192 comes from 3x64 (64 is the block size).

If in theory it’s 168 bits key length, it has been degraded to 112 due to vulnerabilities.

From NIST 800-57:

“One might expect that 3TDEA would provide 56×3 = 168 bits of strength. However, there is an attack on 3TDEA that reduces the strength to the work that would be involved in exhausting a 112 bit key”

---

<div class="post-metadata">

**Author:** ![Baalawi\_242346](https://avatars.discourse-cdn.com/v4/letter/b/48db29/32.png) [@Baalawi\_242346](https://community.f5.com/u/Baalawi_242346)\
**Post date:** [September 15, 2016, 7:26pm UTC](https://community.f5.com/t/des-cbc3-sha-listed-as-192-bits-but-ssl-labs-reports-as-112-bit/9748/4 "2016-09-15T19:26:04Z")

</div>

This link will answer your question:

SOL17296: The BIG-IP system incorrectly reports a 192-bit key length for cipher suites using 3DES (DES-CBC3)

> **[404 Page not found | BIG-IP Documentation](https://techdocs.f5.com/kb/en-us/solutions/public/17000/200/sol17296.html)**
>
> Usage information and technical documentation for BIG-IP and other related F5 products
