08-27-2025 06:22 AM
Is there a way to disable weak cipher keys encryption on the Zone Director 1200 using version 10.5.0.0 build 190?
Security scan revealed there is weak cipher keys used.
08-29-2025 02:31 PM
Please see my reply to pranav for the correct syntax.
I want to comment though that although your security scan has identified a theoretical problem with your ciphers, there are several critical security vulnerabilities in your version of ZoneDirector with public exploit code available.
Ruckus silently fix many vulnerabilities, so even if there weren't a bunch of high risk CVEs for your version of ZoneDirector, your business really must keep up to date with ZoneDirector software updates. So unless this is purely a box-ticking exercise, I recommend scheduling an upgrade to 10.5.1 (GA Refresh 9), and then staying up to date with subsequent releases.
Do note that the latest releases have tightened security a lot, so if you have a firewall between your ZD and APs then you'll need to remove the passive FTP rules and put in some new rules to allow HTTPS. Since I already did this, and it's not well documented, I have a page here describing the firewall changes I made.
