I tried an audit of our Wingftp HTTPS service with this service https://www.ssllabs.com/ssltest/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow.
With very bad results:
This server is vulnerable to the POODLE attack. If possible, disable SSL 3 to mitigate. Grade capped to C.
This server supports weak Diffie-Hellman (DH) key exchange parameters. Grade capped to B.
This server accepts RC4 cipher, but only with older protocol versions. Grade capped to B.
The server does not support Forward Secrecy with the reference browsers.
I installed the latest release 4.7.8 and FIPS 140-2 Mode is activated.
I am missing the possibilities to configure/deactivate
SSL3, RC4 cipher, weak DH key exchange parameters.
We suppress with group policies that IE browser accepts ssl2.0 , ssl3.0 .
This is maybe the reason why we cant use IE for accessing to https wingftp service .

IE 11 & edge doesnt support RC4 chiper anymore: https://support.microsoft.com/en-us/kb/3151631" rel="nofollow
Dueto we have in next weeks an IT-audit for IDW330 and ISO27000 we need a
solution really fast.
Kindly regards,
Michael
Wing FTP Server
English
Deutsch
简体中文