Bug ID 563488: Support Extended Master Secret Extension (RFC7627) for ProxySSL

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6

Fixed In:
13.0.0

Opened: Dec 17, 2015

Severity: 2-Critical

Related Article: K34019109

Symptoms

In ProxySSL, if a client and backend server negotiated and agreed to use Extended Master Secret, ProxySSL will not be able to finish the handshake successfully.

Impact

ProxySSL will not work.

Conditions

ProxySSL is enabled in BIG-IP and the client and server both support Extended Master Secret and successfully exchang the Extended Master Secret Extensions.

Workaround

Do not enable Extended Master Secret features in client or server.

Fix Information

ProxySSL now supports Extended Master Secret Extension (RFC7627) for ProxySSL.

Behavior Change

If the client and the server exchanges extended master secret extension in its client hello or server hello, and agree to use extended master secret calculation, then BIGIP SSL will use the agreed calculation method. There is no hardware support for extended master secret computation, only software path.

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips