Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 
Custom Alert Banner

The SSL/TLS service uses Diffie-Hellman groups with insufficient strength (key size < 2048).

qusai
Nimbostratus
Nimbostratus

We have an issue with Diffie Helman Key after auto scan , how we can increase the Diffie helman Key to 2048

1 REPLY 1

CA_Valli
MVP
MVP

According to K89130356 , all of BIG-IP current versions use only 1024-bit group for DH/DHE ciphers. F5 does not have support for 2048-bits yet implemented at the time of creation of this article. There is an internal RFE opened for this feature.

 

You can tune your cipher list to remove support for DH and DHE protocols for key exchange, so that only Elliptic Curve ECDH/ECDHE suites will be negotiated in SSL handshake.