Loading...
Loading...
When the BIG-IP system uses Proxy-SSL mode, and the virtual server receives a fragmented SSL handshake message, SSL handshake might fail.
If the system receives SSL Fragmented SSL handshake message, SSL handshake is rejected.
1. BIG-IP (VIP) uses Proxy-SSL mode. 2. The BIG-IP system receives a fragmented SSL handshake message (this is especially common when the certificate message is larger than 16 KB, which requires it to be fragmented).
The only workaround is to trim down the list of acceptable client CAs advertised in the CertificateRequest message.(specifically, use client certificate chains that are smaller than 16 KB).
The system now checks whether the SSL handshake message is fragmented by comparing the message length and the handshake record length. The system then assembles the fragmented message and performs the required correctness check if it is fragmented.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.