post quantum cryptography
2 TopicsForce Client-SSL Profile to X25519, Instead of Post-Quantum Cryptography
There is a TLS implementation that was working perfectly before, even though, there is SSL ClientHello extension addition, by a middle-box device. With Clienthello packets of 540bytes, this worked perfectly. An example is the "Extension Unknown Type 17516" added there. Recent tests show the extension addition is no longer working. The only significant change is that CLIENTSSL HELLO packets are now fragmented on TLS 1.3 with the Post-Quantum Cryptography implementation on clients (browsers), with CLIENTSSL HELLO now regularly abover 1500 bytes causing fragmentation. How is it possible if F5 is Client-side server to force all clients to use X25519 ciphers instead of X25519Kyber512Draft00 and X25519Kyber768Draft00 to ensure that full flow is not broken. is there any changes on CLIENTSSL Profile to implement this. Traffic Flow is Mobile browser--Mobile Packet gateway (header enrichment)-- F5 (Server)8Views0likes0CommentsUnable to enable Post Quantum Cryptography (PQC) on BIG-IP Next 20.3.0
Hi experts, Can anyone please help regarding enabling the PQC feature on the Client-Side TLS Protocol/Profile? I have followed the following article and added all the necessary configs but a warning symbol still persists on General Properties and I am unable to proceed forward: https://my.f5.com/manage/s/article/K000148294 If this is a bug, then please rectify it at the earliest. I have attached a screenshot as well.272Views0likes1Comment