# \#cipher

**URL:** https://community.f5.com/tag/cipher/651.md

[Latest](https://community.f5.com/latest.md) · [Categories](https://community.f5.com/categories.md) · [Tags](https://community.f5.com/tags.md)

---

## [Breaking Down the Quantum Challenge: TLS Cipher Suite Vulnerabilities and FIPS Post-Quantum Standards Explained](https://community.f5.com/t/breaking-down-the-quantum-challenge-tls-cipher-suite-vulnerabilities-and-fips-post-quantum-standards-explained/76571)

<div class="topic-metadata">

**Author:** [@Chase\_Abbott](https://community.f5.com/u/Chase_Abbott)\
**Replies:** 0\
**Last updated:** [October 1, 2025, 12:00pm UTC](https://community.f5.com/t/breaking-down-the-quantum-challenge-tls-cipher-suite-vulnerabilities-and-fips-post-quantum-standards-explained/76571 "2025-10-01T12:00:00Z")

</div>

Our Cipher Landscape and Quantum Considerations Understanding quantum computing’s impact on current classical cryptography provides us a foundation for effective post-quantum cryptography migration planning. Current TLS …

---

## [Relation between Cipher-Suite and Key-type of server certificate](https://community.f5.com/t/relation-between-cipher-suite-and-key-type-of-server-certificate/74763)

<div class="topic-metadata">

**Author:** [@Stefan\_Klotz](https://community.f5.com/u/Stefan_Klotz)\
**Replies:** 2\
**Last updated:** [July 5, 2024, 11:54am UTC](https://community.f5.com/t/relation-between-cipher-suite-and-key-type-of-server-certificate/74763 "2024-07-05T11:54:02Z")

</div>

I must noticed/learned these days, that specific allowed ciphers are useless if they are not matching with the key-type of the server-certificate from the clientSSL profile. I think it’s not unusual that most server-cer…

---

## [Block CBC](https://community.f5.com/t/block-cbc/74466)

<div class="topic-metadata">

**Author:** [@RoadRunnerA](https://community.f5.com/u/RoadRunnerA)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 10:41am UTC](https://community.f5.com/t/block-cbc/74466 "2024-05-08T10:41:17Z")

</div>

Hi there, I’m having a challenge on Blocking entirely the CBC cipher. The ciphers I’m using are: ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA384 ECDHE-ECDS…

---

## [CBC ciphers in relation to RFC7366 Encrypt-then-MAC](https://community.f5.com/t/cbc-ciphers-in-relation-to-rfc7366-encrypt-then-mac/72313)

<div class="topic-metadata">

**Author:** [@Stefan\_Klotz](https://community.f5.com/u/Stefan_Klotz)\
**Replies:** 13\
**Last updated:** [September 22, 2023, 6:45am UTC](https://community.f5.com/t/cbc-ciphers-in-relation-to-rfc7366-encrypt-then-mac/72313 "2023-09-22T06:45:33Z")

</div>

Good morning, there is a recommendation from German federal security office to still allow CBC-mode ciphers as long as TLS extention “Encrypt-then-MAC” (RFC7366) is in use. But I can’t find any information how F5 curren…

---

## [How to find which cipher suit is used or not?](https://community.f5.com/t/how-to-find-which-cipher-suit-is-used-or-not/69297)

<div class="topic-metadata">

**Author:** [@kridsana](https://community.f5.com/u/kridsana)\
**Replies:** 1\
**Last updated:** [February 28, 2022, 9:43am UTC](https://community.f5.com/t/how-to-find-which-cipher-suit-is-used-or-not/69297 "2022-02-28T09:43:45Z")

</div>

For example we have cipher suite as below ECDHE-RSA-AES128-GCM-SHA256 (0xc02f) SHA256 ECDHE-RSA-AES128-CBC-SHA (0xc013) SHA ECDHE-RSA-AES128-SHA256 (0xc027) SHA256 How can we know which cipher suit is used…

---

## [Strategy for updating large amount of SSL profiles associated with a single virtual server](https://community.f5.com/t/strategy-for-updating-large-amount-of-ssl-profiles-associated-with-a-single-virtual-server/54003)

<div class="topic-metadata">

**Author:** [@Cole](https://community.f5.com/u/Cole)\
**Replies:** 1\
**Last updated:** [March 16, 2021, 10:32pm UTC](https://community.f5.com/t/strategy-for-updating-large-amount-of-ssl-profiles-associated-with-a-single-virtual-server/54003 "2021-03-16T22:32:05Z")

</div>

I’m looking to shed some of the older ciphers that are a part of the DEFAULT cipher string in our SSL profiles. The problem is, we host quite a few SSL profiles (100+) with a single virtual server. I discovered that I’m …

---

## [How to list all cipher keywords](https://community.f5.com/t/how-to-list-all-cipher-keywords/52438)

<div class="topic-metadata">

**Author:** [@jwlarger](https://community.f5.com/u/jwlarger)\
**Replies:** 4\
**Last updated:** [March 3, 2021, 7:34am UTC](https://community.f5.com/t/how-to-list-all-cipher-keywords/52438 "2021-03-03T07:34:40Z")

</div>

Can I query from tmos or cli to list all valid cipher keywords? (Not tmm --clientciphers DEFAULT - I just want keywords like !TLSv1 and the like). If not, is there a list online? I searched the kb, here, & the web wit…

---

## [Cipher negotiated between F5 and Node](https://community.f5.com/t/cipher-negotiated-between-f5-and-node/48972)

<div class="topic-metadata">

**Author:** [@prashanth](https://community.f5.com/u/prashanth)\
**Replies:** 6\
**Last updated:** [December 8, 2020, 1:00pm UTC](https://community.f5.com/t/cipher-negotiated-between-f5-and-node/48972 "2020-12-08T13:00:54Z")

</div>

Hi There, We are currently in the process of upgrading F5 from v12 to v13. We came across an issue due to depreciated ciphers. Some of our VIPs were using the DEFAULT cipher suite and since some legacy ciphers were depr…

---

## [How to build very specific Cipher string?](https://community.f5.com/t/how-to-build-very-specific-cipher-string/58603)

<div class="topic-metadata">

**Author:** [@Hugo\_van\_der\_K1](https://community.f5.com/u/Hugo_van_der_K1)\
**Replies:** 3\
**Last updated:** [March 12, 2020, 8:43pm UTC](https://community.f5.com/t/how-to-build-very-specific-cipher-string/58603 "2020-03-12T20:43:33Z")

</div>

How can I specify a very specific Cipher string? The object is to only allow the ciphers below and offer them in this specific order. TLS13-AES256-GCM-SHA384/TLS1.3 TLS13-CHACHA20-POLY1305-SHA256/TLS1.3 TLS13-AES12…

---

## [Strong cipher suite](https://community.f5.com/t/strong-cipher-suite/50509)

<div class="topic-metadata">

**Author:** [@Koalan](https://community.f5.com/u/Koalan)\
**Replies:** 2\
**Last updated:** [October 1, 2019, 11:30am UTC](https://community.f5.com/t/strong-cipher-suite/50509 "2019-10-01T11:30:46Z")

</div>

Hi we are testing a url on sslab test and the current setup on our f5 have these ciphers: DEFAULT:!SSLv2:!SSLv3:!TLSv1:!RSA:!ECDHE-RSA-AES256-CBC-SHA:!ECDHE-RSA-AES128-CBC-SHA:!ECDHE-RSA-DES-CBC3-SHA:!EXPORT:!DHE+AES-GC…

---

## [Lightboard Lessons:  What is a TLS Cipher Suite?](https://community.f5.com/t/lightboard-lessons-what-is-a-tls-cipher-suite/66167)

<div class="topic-metadata">

**Author:** [@ltwagnon](https://community.f5.com/u/ltwagnon)\
**Replies:** 2\
**Last updated:** [January 15, 2019, 3:54am UTC](https://community.f5.com/t/lightboard-lessons-what-is-a-tls-cipher-suite/66167 "2019-01-15T03:54:57Z")

</div>

When a web client (Internet browser) connects to a secure website, the data is encrypted. But, how does all that happen? And, what type of encryption is used? And, how does the Internet browser know what type of encrypti…

---

## [Cipher string mismatch ??](https://community.f5.com/t/cipher-string-mismatch/40008)

<div class="topic-metadata">

**Author:** [@Spela\_317265](https://community.f5.com/u/Spela_317265)\
**Replies:** 5\
**Last updated:** [December 30, 2018, 8:08am UTC](https://community.f5.com/t/cipher-string-mismatch/40008 "2018-12-30T08:08:45Z")

</div>

Hi, I configured SSL cipher string, to support 6 different ciphers: config tmm --clientciphers TLSv1\_2+ECDH-RSA-AES256-GCM-SHA384:TLSv1\_2+ECDH-RSA-AES256-SHA384:TLSv1\_2+ECDH-RSA-AES256-SHA:TLSv1\_2+DHE-RSA-AES256-SHA256…

---

## [Lightboard Lessons:  What Are AEAD Ciphers?](https://community.f5.com/t/lightboard-lessons-what-are-aead-ciphers/66232)

<div class="topic-metadata">

**Author:** [@ltwagnon](https://community.f5.com/u/ltwagnon)\
**Replies:** 0\
**Last updated:** [May 23, 2018, 2:39am UTC](https://community.f5.com/t/lightboard-lessons-what-are-aead-ciphers/66232 "2018-05-23T02:39:00Z")

</div>

The recent TLS 1.3 protocol mandates that Authenticated Encryption with Associated Data (AEAD) Ciphers be used for bulk encryption. As web servers and browsers transition to using these ciphers, it’s important to know wh…

---

## [Bigip 11.2.1 - weak ciphers](https://community.f5.com/t/bigip-11-2-1-weak-ciphers/47145)

<div class="topic-metadata">

**Author:** [@Sabir\_Alvi](https://community.f5.com/u/Sabir_Alvi)\
**Replies:** 3\
**Last updated:** [February 16, 2018, 10:08am UTC](https://community.f5.com/t/bigip-11-2-1-weak-ciphers/47145 "2018-02-16T10:08:58Z")

</div>

I have BiGIP 11.2.1 in my test lab and below Cipher suite for SSL profile: TLSv1\_2:!SSLv3:!RC4-SHA:!3DES:!DH:!ADH:!EDH:!MD5:!EXPORT:!DES:@STRENGTH However there are few open weak ciphers when I scan -- \[TLS\_RSA\_…

---

## [SSL Cipher tweaking](https://community.f5.com/t/ssl-cipher-tweaking/21473)

<div class="topic-metadata">

**Author:** [@Bciesz\_171056](https://community.f5.com/u/Bciesz_171056)\
**Replies:** 3\
**Last updated:** [February 2, 2018, 3:47pm UTC](https://community.f5.com/t/ssl-cipher-tweaking/21473 "2018-02-02T15:47:05Z")

</div>

Hi, To be honest i do not completely understand how the cipher string is constructed, but I normally use this one, that used to give me grade A on ssllabs: !LOW:!SSLv2:!SSLv3:!MD5:!RC4+SHA:!EXPORT:!DHE:ECDHE+AES:AES+S…

---

## [Ciphers on profiles](https://community.f5.com/t/ciphers-on-profiles/19710)

<div class="topic-metadata">

**Author:** [@crengifo\_232216](https://community.f5.com/u/crengifo_232216)\
**Replies:** 1\
**Last updated:** [February 2, 2018, 6:52am UTC](https://community.f5.com/t/ciphers-on-profiles/19710 "2018-02-02T06:52:41Z")

</div>

Hi! Maybe this is stupid question, but I need to know if a virtual server, with ssl server and client profiles, would have any issue if on the ssl client profile uses a particular cipher (let’s say TLS\_ECDHE\_RSA\_WITH\_…

---

## [Using v13 Default Cipher in v12](https://community.f5.com/t/using-v13-default-cipher-in-v12/31292)

<div class="topic-metadata">

**Author:** [@Maximilian\_Mar1](https://community.f5.com/u/Maximilian_Mar1)\
**Replies:** 2\
**Last updated:** [July 19, 2017, 8:55am UTC](https://community.f5.com/t/using-v13-default-cipher-in-v12/31292 "2017-07-19T08:55:07Z")

</div>

Hello, im curious if I should use Default Ciphers from the newest BIG-IP version 13 for my F5, using 12.1.0 HF2. Cause the Default Ciphers in v13 are defined by new standards I assume. Does this way of thinking mak…

---

## [01070312:3: Invalid keyword 'ecdhe-ecdsaaes256-  gcm-sha384' in ciphers list for profile](https://community.f5.com/t/01070312-invalid-keyword-ecdhe-ecdsaaes256-gcm-sha384-in-ciphers-list-for-profile/46071)

<div class="topic-metadata">

**Author:** [@cathy\_123](https://community.f5.com/u/cathy_123)\
**Replies:** 3\
**Last updated:** [February 22, 2017, 3:56am UTC](https://community.f5.com/t/01070312-invalid-keyword-ecdhe-ecdsaaes256-gcm-sha384-in-ciphers-list-for-profile/46071 "2017-02-22T03:56:58Z")

</div>

Hi Guys! Does anyone experience the same issue? We are experiencing SSL/TLS Vulnerabilities per our Security Team we need to apply the certain cipher configuration and it includes this string SHA384:ECDHE-ECDSAAES256- G…

---

## [Exact syntax for SSL ciphers](https://community.f5.com/t/exact-syntax-for-ssl-ciphers/9256)

<div class="topic-metadata">

**Author:** [@Alin\_Olar\_24603](https://community.f5.com/u/Alin_Olar_24603)\
**Replies:** 4\
**Last updated:** [February 13, 2017, 12:48pm UTC](https://community.f5.com/t/exact-syntax-for-ssl-ciphers/9256 "2017-02-13T12:48:04Z")

</div>

Hi, Trying to help a coworker with an SSL Client profile request with custom ciphers. So far I have been able to see the ciphers supported on F5 but not the exact syntax when you configure them. I checked the TMSH …

---

## [Disable ECDHE Cipher Suite for Server Side SSL Profile](https://community.f5.com/t/disable-ecdhe-cipher-suite-for-server-side-ssl-profile/33232)

<div class="topic-metadata">

**Author:** [@dpacewam\_309700](https://community.f5.com/u/dpacewam_309700)\
**Replies:** 2\
**Last updated:** [February 9, 2017, 11:49pm UTC](https://community.f5.com/t/disable-ecdhe-cipher-suite-for-server-side-ssl-profile/33232 "2017-02-09T23:49:47Z")

</div>

Hi, We have deployed Imperva WAF in transparent bridge mode between our F5 load balancers and Web Servers. In order to perform SSL Decryption, we need to disable certain Cipher Suites including ECHDE and EDH. I have c…

---

## [SSL Cipher error in ltm logfile "Cipher XX:Y negotiated is not configured in profile \<sslprofilename\>"](https://community.f5.com/t/ssl-cipher-error-in-ltm-logfile-cipher-xx-y-negotiated-is-not-configured-in-profile-sslprofilename/54139)

<div class="topic-metadata">

**Author:** [@Joe\_Volesky\_969](https://community.f5.com/u/Joe_Volesky_969)\
**Replies:** 7\
**Last updated:** [October 11, 2016, 2:02am UTC](https://community.f5.com/t/ssl-cipher-error-in-ltm-logfile-cipher-xx-y-negotiated-is-not-configured-in-profile-sslprofilename/54139 "2016-10-11T02:02:55Z")

</div>

I recently moved an HTTPS Virtual Server from an old LTM (running 9.3.1) to a new pair of load balancers running 11.4.1. This particular Virtual Server is using both a client SSL profile and a server SSL profile, pointin…

---

## [Cipher Suite Ordering](https://community.f5.com/t/cipher-suite-ordering/11212)

<div class="topic-metadata">

**Author:** [@NetworkTeam\_178](https://community.f5.com/u/NetworkTeam_178)\
**Replies:** 3\
**Last updated:** [February 11, 2016, 8:23am UTC](https://community.f5.com/t/cipher-suite-ordering/11212 "2016-02-11T08:23:14Z")

</div>

I need to order my ciphers in a very specific way. Using this command 'tmm --clientciphers ‘ECDHE+AES-GCM:ECDHE+AES:’ I get; ID SUITE BITS PROT METHOD CIPHER MAC KEYX 49200 ECDHE…

---

## [iRule to provide CIPHER for specifc hosts](https://community.f5.com/t/irule-to-provide-cipher-for-specifc-hosts/53025)

<div class="topic-metadata">

**Author:** [@adcounts](https://community.f5.com/u/adcounts)\
**Replies:** 1\
**Last updated:** [August 17, 2015, 6:05pm UTC](https://community.f5.com/t/irule-to-provide-cipher-for-specifc-hosts/53025 "2015-08-17T18:05:30Z")

</div>

I am running into a situation that I think I can fix with an iRule but don’t know how to go about writing it. I need to control the CIPHER that is presented to a Client but want it to be different based on the Source Add…

---

## [Need to configure specific Cipher "AES256-SHA256" in server SSL profile](https://community.f5.com/t/need-to-configure-specific-cipher-aes256-sha256-in-server-ssl-profile/19496)

<div class="topic-metadata">

**Author:** [@Mohanish\_169493](https://community.f5.com/u/Mohanish_169493)\
**Replies:** 5\
**Last updated:** [July 22, 2015, 7:12pm UTC](https://community.f5.com/t/need-to-configure-specific-cipher-aes256-sha256-in-server-ssl-profile/19496 "2015-07-22T19:12:29Z")

</div>

Hi, Please if someone can guide me as to how to configure specific cipher “AES256-SHA256” for server SSL profile. The server side certificate is using “AES256-SHA256” so they want it to use this. I am using version 11…

---

## [ECC Ciphers in 11.4.1](https://community.f5.com/t/ecc-ciphers-in-11-4-1/57166)

<div class="topic-metadata">

**Author:** [@Mike\_Maher](https://community.f5.com/u/Mike_Maher)\
**Replies:** 1\
**Last updated:** [June 1, 2015, 4:26pm UTC](https://community.f5.com/t/ecc-ciphers-in-11-4-1/57166 "2015-06-01T16:26:02Z")

</div>

I am having some trouble getting ECDHE ciphers to function. I am running 11.4.1 and have tried multiple cipher strings in the SSL profile, but I can’t seem to get them to appear when I scan the VIP. I always seem to get …

---

## [128 bit encryption for citrix connections](https://community.f5.com/t/128-bit-encryption-for-citrix-connections/10150)

<div class="topic-metadata">

**Author:** [@Greg\_130338](https://community.f5.com/u/Greg_130338)\
**Replies:** 1\
**Last updated:** [December 13, 2013, 4:07pm UTC](https://community.f5.com/t/128-bit-encryption-for-citrix-connections/10150 "2013-12-13T16:07:40Z")

</div>

We’d like to up the TLS encryption key size to 256 from 128 for our citrix connections. I’m assuming a change needs to be made to the client SSL profile, specifically the cipher, which is currently set to DEFAULT. I unde…

---

## [SSL Client profile: can't activate SSLv2](https://community.f5.com/t/ssl-client-profile-cant-activate-sslv2/33566)

<div class="topic-metadata">

**Author:** [@Joeri\_45317](https://community.f5.com/u/Joeri_45317)\
**Replies:** 4\
**Last updated:** [October 10, 2013, 12:18pm UTC](https://community.f5.com/t/ssl-client-profile-cant-activate-sslv2/33566 "2013-10-10T12:18:13Z")

</div>

We have an Exchange 2010 CAS setup, when we enable SSL offloading, some of our “legacy” clients can’t use Outlook Anywhere anymore. We suspect the old clients can’t agree on a cipher with the F5. I ran sslscan towards…
