Loading...
Loading...
The BIG-IP system sends back an FFDHE key share that forces the client to also use FFDHE, even if the client sent a key share that is still acceptable to the BIG-IP.
Clients are forced to use the FFDHE group for its key share even if the client sent a key share that is still acceptable to the BIG-IP
The BIG-IP system is configured to prefer an FFDHE DH group and the client sends the same FFDHE DH group as supported but sends a key share for a different DH group.
Either remove the FFDHE groups, or reorder DH group preferences so that FFDHE groups are not preferred over other groups.
None
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.