Forum Discussion
Ntinos
Nimbostratus
Sep 10, 2020TLS 1.3 and BIG-IP Virtual Edition - BEST
Has there been any changes in the way TLS 1.3 is configured in AWS BEST AMIs after 15.0.1.1 0.0.3 build. Same config works fine with no error on F5 BIG-IP Virtual Edition - BEST 15.0.1.1 0.0.3 and F5...
Lidev
Nacreous
Sep 17, 2020Have you try the same test (openssl s_clien)t but with tls1.2 to see if the result is the same (certificate expired)?
openssl s_client -tls1_2 -connect 20.0.5.25:443Lidev
Nacreous
Sep 17, 2020Okay, makes a tcpdump or ssl dump and compares the Ciphers Suites negotiated with the client during the SSL Handshake.
TLS 1.3 has eliminated support for algorithms and ciphers that are practically vulnerable.
- RC4 Stream Cipher
- RSA Key Exchange
- SHA-1 Hash Function
- CBC (Block) Mode Ciphers
- MD5 Algorithm
- Various non-ephemeral Diffie-Hellman groups
- EXPORT-strength ciphers
- DES
- 3DES
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects