Bug ID 2311605: Updated Common Criteria cipher suite list to include TLS1.3 ciphers and excludes SHA1 based ciphers.

Last Modified: Jul 28, 2026

Affected Product(s):
BIG-IP LTM(all modules)

Fixed In:
21.1.0.1

Opened: Jun 03, 2026

Severity: 3-Major

Symptoms

The Common Criteria cipher suite list did not have the TLS1.3 ciphers and also contains SHA-1-based cipher suites

Impact

Virtual server fails to connect with TLS1.3 cipher suites and also accepts connections with SHA1-based ciphers

Conditions

- Configure clientssl and serverssl with "f5-cc-stip-ciphers" or "f5-cc-ciphers" - Configure virtual server with the same clientssl or serverssl profile

Workaround

Create a custom cipher-rule which includes TLS1.3 ciphers and excludes SHA-1-based ciphers

Fix Information

Updated the Common Criteria cipher list

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips