# Enabling ECDHE-ECDSA Ciphers TMOS 15.1.10.x

**URL:** <https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817>\
**Category:** Technical Forums\
**Tags:** application-delivery\
**Created:** [January 10, 2024, 9:11pm UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817 "2024-01-10T21:11:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HetmanG](https://avatars.discourse-cdn.com/v4/letter/h/e56c9b/32.png) [@HetmanG](https://community.f5.com/u/HetmanG)\
**Post date:** [January 10, 2024, 9:11pm UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/1 "2024-01-10T21:11:43Z")

</div>

Hello,

To meet security requirements, I am attempting to enable TLS 1.3 as well as turn off insecure ciphers including CBC Ciphers and all other insecure Ciphers. &nbsp;I built a Cipher Group which includes f5-secure as ‘Allow’, f5-secure in the ‘Allowed List’ and then built an ‘Exclude’ that includes a rule which contains the cipher string:

AES:CAMELLIA:DES:RC4:AES256-GCM-SHA384:AES128-GCM-SHA256

This seems to work in that it restricts all bad ciphers which I do not want available. &nbsp;When I look at the Group Audit, I see the following enabled:

Cipher Suites

ECDHE-RSA-AES256-GCM-SHA384/TLS1.2  
ECDHE-RSA-CHACHA20-POLY1305-SHA256/TLS1.2  
ECDHE-ECDSA-AES256-GCM-SHA384/TLS1.2  
ECDHE-ECDSA-CHACHA20-POLY1305-SHA256/TLS1.2  
TLS13-AES256-GCM-SHA384/TLS1.3  
TLS13-CHACHA20-POLY1305-SHA256/TLS1.3  
ECDHE-RSA-AES128-GCM-SHA256/TLS1.2  
ECDHE-ECDSA-AES128-GCM-SHA256/TLS1.2  
TLS13-AES128-GCM-SHA256/TLS1.3

The issue I am having is when I run an NMAP scan or hit the VIP with SSL Labs, I only get 6 Ciphers which do not include the ECDHE-ECDSA ciphers which should be TLS 1.2 Ciphers. &nbsp;Under the client ssl profile, I removed the disable TLS 1.3 option, so we should be good there. &nbsp;Is there anything else that specifically needs to be enabled to allow the BigIP device to support ECDHE-ECDSA ciphers? &nbsp;Running 15.1.10.x series.

Anyone have any ideas on this?

---

<div class="post-metadata">

**Author:** ![Michael\_Saleem](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/michael_saleem/32/7239_2.png) [@Michael\_Saleem](https://community.f5.com/u/Michael_Saleem)\
**Post date:** [January 10, 2024, 10:18pm UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/2 "2024-01-10T22:18:54Z")

</div>

Your NMAP scan will only show ECDSA ciphers if you have an ECDSA SSL certificate terminated on the VIP. I suspect that you are using an RSA SSL certificate, which is why you will only see RSA based ciphers.

---

<div class="post-metadata">

**Author:** ![PSFletchTheTek](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@PSFletchTheTek](https://community.f5.com/u/PSFletchTheTek)\
**Post date:** [January 19, 2024, 1:23pm UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/3 "2024-01-19T13:23:15Z")

</div>

Hi&nbsp; @HetmanG ,

Did you get this sorted? - I have had the same experiance and would agree with&nbsp; @Michael_Saleem , it does seem like you are using a RSA cert so only those ciphers are being seen.

---

<div class="post-metadata">

**Author:** ![AddisynWard](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@AddisynWard](https://community.f5.com/u/AddisynWard)\
**Post date:** [February 7, 2024, 9:29am UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/4 "2024-02-07T09:29:21Z")

</div>

I want to ask a similar question, can I ask it?

---

<div class="post-metadata">

**Author:** ![whisperer](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/whisperer/32/13906_2.png) [@whisperer](https://community.f5.com/u/whisperer)\
**Post date:** [February 7, 2024, 11:55pm UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/5 "2024-02-07T23:55:36Z")

</div>

I would start a separate thread, so that is more visibility and separation of issues/solutions.

---

<div class="post-metadata">

**Author:** ![whisperer](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/whisperer/32/13906_2.png) [@whisperer](https://community.f5.com/u/whisperer)\
**Post date:** [February 8, 2024, 12:00am UTC](https://community.f5.com/t/enabling-ecdhe-ecdsa-ciphers-tmos-15-1-10-x/73817/6 "2024-02-08T00:00:58Z")

</div>

I would mark @Michael_Saleem reply as the solution here.

> ECDSA ciphers require that the server has an ECC certificate. It is likely that you have only a RSA certificate though (which is the common case), which means that ECDSA ciphers will not be supported even if they are configured.
