How to disable weak or medium SSL ciphers?

If you failed a PCI Compliance scan, it doesn't matter, if you care about it, you can disable weak and medium SSL ciphers in Wing FTP Server, you just need to enable the option "Enable FIPS 140-2 mode" under "Server > Settings > General Settings > Security". Then Wing FTP Server will use the algorithms which be approved by the FIPS group (only allows strong SSL ciphers).


After you change this option, you need to restart the WingFTP service.

Now you can test the strength of the SSL ciphers again, you can test it with openssl tool, most Linux system will install openssl by default, Windows users can download it from here:

You can type the following commands to check whether the server supports weak or medium SSL ciphers:

openssl s_client -connect -cipher EXP:LOW
openssl s_client -connect -cipher EXP:MEDIUM

If weak or medium SSL ciphers are not supported, you will get an error like this:

140004449822376:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:177:

Otherwise, you will get a result like this:

depth=1 /C=BE/O=GlobalSign nv-sa/CN=GlobalSign Domain Validation CA - G2
