Loading...
Loading...
On a BIG-IP device, whenever a large-sized client certificate is sent by an SSL client to a virtual service, and SSL persistence is enabled, the SSID parser does not reassemble fragmented ClientKeyExchange messages correctly. It interprets the next incoming fragment - part of the CertificateVerify message - as a new record, incorrectly calculates its length and ends up waiting endlessly for more bytes to receive the record.
Client connection hangs during the handshake. No impact to any other module.
When SSL persistence is enabled and a large-sized client certificate is sent by the SSL client to the BIG-IP device.
Disable SSL persistence.
SSL now reassembles fragments correctly with a large-sized client certificate when SSL persistence is enabled.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.