Forum Discussion
OpenSSL and Heart Bleed Vuln
Okay still struggling to get my head around this.
We use 11.4.2 HF2.
We get connections using TLS 1.2 (and some old) using a bespoke set of ciphers including "NATIVE"
I assume the TLS 1.2 connection must be using the NATIVE code, but that we may fall back to older ciphers, and that since the SSL library mod_ssl.so depends on is libssl.so.0.9.8 (readelf -d mod_ssl.so) then this F5 pair are not affected, but that people with 11.5 may be. And I nearly upgraded BECAUSE of the better SSL cipher support in 11.5......
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com