Bug ID 1814821: DHE groups present in profile's cipherlist with TLS1.3 enabled and tmm.ssl.useffdhe set to false simultaneously

Last Modified: Apr 20, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
16.1.5, 16.1.5.1, 16.1.5.2, 17.1.2, 17.1.2.1

Opened: Feb 11, 2025

Severity: 3-Major

Symptoms

You might observe CRIT-level logs of configuration issues in the TMM logs but there is no impact to the traffic. Example log message: crit tmm4[17746]: 01260000:2: Profile /Common/serverssl-secure: DHE groups present in profile's cipherlist with TLS1.3 enabled and tmm.ssl.useffdhe set to false simultaneously.

Impact

Crit-level logs are logged to /var/log/tmm

Conditions

1. The db variable tmm.ssl.useffdhe set to false 2. Virtual server configured to use DH groups

Workaround

Leave the tmm.ssl.useffdhe value to default which is true

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips