Hi All,
I have just implemented some 3030S and migrated some services across in our production environment. The 3030S terminate SSL for the backend services. Out of curiosity I ran some SSL LABS test against the services and they all flagged errors with weak Diffie-Hellman key Exchange Parameters and therefore capped the score at a B.
Where as this is a big improvement on our old Cisco CSS Load Balancers which scored an F due the the fact they did not support anything above SSL v3.0 due their age. I would like to see the score as an A.
I believe the weak DH results are sue to it using common DH primes as the SSL Lab reports later on in the results, it then suggests using custom DH parameters.
My question is - How if possible can I use custom DH parameters in my SSL templates for the Services?
Kind Regards
Ryan