21-Apr-2021 04:08
Dears,
As mentioned in the article https://support.f5.com/csp/article/K53037818 .. TLS servers compliant with the TLS1.2 specification must accept any value as the record layer version number for ClientHello.
It also mentioned that "When you encounter issues with SSL handshakes failing due to the record layer version in the ClientHello message, you should first review the configuration on the TLS server."
As of now, we would like to know where can we see the configuration of TLS record layer version in F5 Client SSL Profile.
Thanks in Advance.
Mohammed Shiraz
21-Apr-2021 06:21
TLS record layer version is not present in client SSL profile. Please check the last part of the doc, where it mentions beginning v 12.1.0, TLS record layer version is used TLS1.0 unless db value is disabled.
Beginning in BIG-IP 11.5.4 HF2 for the BIG-IP 11.5.x branch and BIG-IP 12.1.0 HF1 and later, the ssl.outerrecordtls1_0 database variable is introduced. Prior to this database variable, the version present in the ClientHello and the version present in the outer record match. With the introduction of this database variable, which is enabled by default, the version present in the outer record is TLS 1.0, regardless of the version in the ClientHello. To verify the value of ssl.outerrecordtls1_0, perform the following procedure:
21-Apr-2021 07:20
Thanks for the information Sanjay...
Does this means F5 will accept any version of TLS record layer coming from the client.
Actually, we need a confirmation that our device will accept any version of TLS record layer coming from the client. And how do we confirm this?
Regards
21-Apr-2021 08:05
Please note, ssl.outerrecordtls1_0 this variable is for serverside TLS session. i.e. from F5 to the server where F5 initiates CLIENT HELLO towards the server.
For client side TLS session, as mentioned earlier there is no TLS record layer version option. BIGIP accepts all TLS record layer version, the one which matters is CLIENT HELLO version coming from the client. If that's not matching what is allowed on client ssl profile, BIGIP would reset the connection.
Are you having any issue in particular with this?
21-Apr-2021 09:20
Thanks for your response. Can we have any reference article stating that BIG-IP accepts all TLS record layer versions? Need to provide it to one of the client....
Thanks again for your support...
21-Apr-2021 11:30
Sorry don't have it. I'm telling it from my experience of working with BIGIP quite few years now 🙂
If you are looking for an official doc, you can log a general information support case with F5 and they can provide the link.