Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP LTM
Fixed In:
21.1.0.1
Opened: Dec 02, 2025 Severity: 3-Major
f5-cc-stip-ciphers and f5-cc-ciphers cipher-rule use the DEFAULT DH group. The DEFAULT DH group was adding X25519, which is not a Common Criteria-approved cipher
A virtual server will accept a connection with the X25519 DH group
- Configure clientssl and serverssl with "f5-cc-stip-ciphers" or "f5-cc-ciphers" - Configure virtual server with the same clientssl or serverssl profile
Create a custom cipher rule with the excluded X15529 DH group
Removed X25519 DH group from "f5-cc-stip-ciphers" or "f5-cc-ciphers" cipher-rule