Forum Discussion

Henk_Oostland's avatar
Henk_Oostland
Icon for Nimbostratus rankNimbostratus
Jan 26, 2015

ecit client SSL profile

When i change e client SSL profile to a profile without SSLv3 and no weak ciphers or export grade ciphers, is there any impact on the standin connections?

 

2 Replies

  • Typically configuration changes apply to new established connections only.

     

    Inside an established connection a SSL re-negotiation may happen and a change in the profile may affect this.

     

    To be on the safe side I would recommend to run a test with your current TMOS version and to observe traffic via SSLDUMP.

     

  • Also try creating 2 separate client profiles and inter-changing them to see the affect of the cipher change. And as steve mentioned, ssldump is pretty handy.