Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP LTM
Fixed In:
21.1.0.1
Opened: Jun 03, 2026 Severity: 3-Major
The Common Criteria cipher suite list did not have the TLS1.3 ciphers and also contains SHA-1-based cipher suites
Virtual server fails to connect with TLS1.3 cipher suites and also accepts connections with SHA1-based ciphers
- Configure clientssl and serverssl with "f5-cc-stip-ciphers" or "f5-cc-ciphers" - Configure virtual server with the same clientssl or serverssl profile
Create a custom cipher-rule which includes TLS1.3 ciphers and excludes SHA-1-based ciphers
Updated the Common Criteria cipher list