Skip to main content

SFTP Host Key

SFTP, and its underlying protocol SSH, have a concept of Host Keys, which is a way for clients to confirm using secure cryptography that they are connecting to the correct server (host).

Ordinarily in SSH, each host will use a unique host key that is generated by and associated with each host.

In a business-to-business service such as SFTP, one host key is used persistently over time so clients always recognize the service when connecting.

Files.com Default SFTP Host Keys

Files.com presents an RSA host key to all SFTP clients that support RSA. For clients that do not support RSA but do support ED25519, Files.com presents an ED25519 host key instead. Clients that support both key types always receive the RSA key, regardless of their stated preference order.

This ensures that our adding support for ED25519 does not cause host key mismatch errors for any connections already using the RSA key.

RSA Host Key

Files.com uses a 4096-bit RSA SSH host key. The host key itself (in OpenSSH format) and fingerprints in three different formats are provided below. Use whichever format is required by your SFTP app.

OpenSSH host key: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCD+pdvc7zeWkcDuyo4k7fca+BVqSSnbGteq2fcquo+jbN9rXySnlbHyAZsxwXIxn/TMWFQCgD619TbdMQ2F4x0tC/UfrNiF0tCQ0UZNlOuQz6G2a0QBzMRgeugGqbFOHHQTaOcgMJoW0ai8vbpHlGMybqcjQg+MWC8fNl4WcX9Ruze713WhcTIbrA4P7iqlyjFkiaQMX642mO0/RboME/4TdyNg7w0bxJaLifiIGtStZ5cRWSW8nxr/PEdQPeSg/2HshyUFJx6GD7ej3NeFsDuYCYFdBXGpZ/Tp6i2mIC/NoVO+3Hz7Pw6JA+H3tEy8U9zqSwPk9RIGlKoWTtZvo9xcBwCFIPyMymU83gfioZYZN4uK196oX/2sspMUIOTUlA4eeIdmbDbK0w1QYGr1bOk/5bKgxybDx4m7FsY3NDylZKDmS1SMVPg1C/GYVdpheOHZpzH5f8qT34ZRFGmktIhRqD+cSiNdcDMDebRBeFG/mCIVSNnoEiDKjKqH/+dpdiJHlTDSH1QCg/d+HSX4eEVG0AudIeSELjaJg2V0kVbk9gF28G0BzQ6NxGm9d7hZD61BfjcuxgRr1bqx6uEip0WrNTinNEIleB1L6M5BUapeICBe+F0Kte+qBYrVENWJoai9V9l/IuBvYWIWkMf0MsuGeiQi2IOvEMfwrD9jBlWqw==

SHA256 fingerprint: JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw

SHA1 fingerprint: go2g72JG1emRzP54QtFmFrE0DTg

SHA1 hex digest: 82:8d:a0:ef:62:46:d5:e9:91:cc:fe:78:42:d1:66:16:b1:34:0d:38

MD5 fingerprint: 79:e1:fc:1c:8d:d7:95:25:84:c5:70:16:4d:07:e0:c5

Please refer to the documentation for your specific SFTP client for exact details about how to use a host key fingerprint.

For example, WinSCP provides host key fingerprint capabilityExternal LinkThis link leads to an external website and will open in a new tab via its -hostkey option. When using the WinSCP command line, you can specify:

-hostkey="ssh-rsa 4096 JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw"

When using the WinSCP Script Command option, you can specify:

open sftp://user:XXXXX@[subdomain].files.com -timeout=30 -privatekey=C:\path\to\my-private.key -hostkey="ssh-rsa 4096 JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw"

ED25519 Host Key

Files.com uses an ED25519 SSH host key for clients that do not support RSA. This key is only presented when the connecting client advertises no support for RSA. Clients that support both RSA and ED25519 always receive the RSA key instead, regardless of client preference order. The host key itself (in OpenSSH format) and fingerprints in multiple formats are provided below.

OpenSSH host key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOH0/3culh5tgsVyIsH5gu8cCpKmoimc2w+cTm3CHHHo

SHA256 fingerprint: 1mU7ovnpCSl9X523W40erKu1JipY4LzMb5co4I4+N6A

SHA1 fingerprint: aFlJi9yw2UkcJHsyQ0+S+iFdgLM

SHA1 hex digest: 68:59:49:8b:dc:b0:d9:49:1c:24:7b:32:43:4f:92:fa:21:5d:80:b3

MD5 fingerprint: 74:d6:34:42:7e:d6:4e:c3:41:bc:39:7c:00:51:ab:6a

ExaVault SFTP Host Key Fingerprints

For sites configured to use the ExaVault host key, use the appropriate format listed here for your SFTP client to check the host key.

OpenSSH Host key ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDk7ZSzE4vqFaZoLCpErMNFz81iT+EIXifOT+TYwPozcq16lOWUAa2EyG/xSAK5l5otYG8fdTt8H8HeDYKaxWo4vQ2bLNuiVUlGTUAUxjxhAZGJzed/gfID/RnOStnabZIT9ElOObv5U0ZKgDrvsbjbB8Y51XxfwaqqXtIq/WIIstpX4sjTOpM3YmuY8OLbd/p0SQcjTg5PFlIgQuRX8hOo811lQzbp9t2QsUEhMcKGAPsRCM/nbn3p8/JD0nc3PtjKolrLfsBaR9aDwkV/b9SprpcBXrVvmHIhg5qjt88r7QW0f8MJiYkuQsG80g7VtlKf+OUGTR93+hNrXSmZp5F3

SHA256 fingerprint: BafxoY7Md78+Iwj2Chcv/kRIO2ZH2EpNuL5H42WiDJY

SHA1 fingerprint: KfsbIcTkzl5tFqH30AqNHeJDq2s

SHA1 hex digest: 29:fb:1b:21:c4:e4:ce:5e:6d:16:a1:f7:d0:0a:8d:1d:e2:43:ab:6b

MD5 fingerprint: 0e:ce:3e:a2:be:7e:45:1f:0b:dd:c5:41:e0:96:c9:b7

SmartFile SFTP Host Key Fingerprints

For sites configured to use the SmartFile host key, use the appropriate format listed here for your SFTP client to check the host key.

SHA256 fingerprint 1: npYmj8dqQjp3XqH1VVlOSjW2CbcSrt43bXDMzNXkKxs

MD5 fingerprint 1: 8e:15:c8:81:c2:1f:23:a2:64:82:76:40:8c:12:58:40

SHA256 fingerprint 2: g+kpwxVcKZAqFFbwpG/c44yACwMzzEENQlKN4EzQRO4

MD5 fingerprint 2: b8:65:5e:f5:e0:9f:0d:83:9e:3d:da:b0:fb:12:b0:68

Customizing the SFTP Host Key

When migrating SFTP services from another vendor or an on-premises environment to Files.com, you can continue using any host key that is already in use.

Files.com lets you customize your SFTP host key so that migrating existing SFTP services to the Files.com platform is smooth.

You can configure your SFTP host key in the SFTP Host Key section of the Encryption settings of your Files.com site.

The available Host Key Provider options are:

  • Files.com Host Key (default)
  • ExaVault Host Key
  • SmartFile Host Key
  • Custom Host Keys

Files.com Host Key

The Files.com Host Key option uses the Files.com SFTP host key described above. This is the default.

ExaVault Host Key

ExaVault is another Managed File Transfer service that Files.com acquired in 2021. The ExaVault Host Key option uses the ExaVault SFTP host key and is provided for customers who have migrated from the ExaVault platform to the Files.com platform.

As of mid-2023, the ExaVault host key was only available in our USA region. We expect to bring the ExaVault host key to all regions very soon.

SmartFile Host Key

SmartFile is another Managed File Transfer service that Files.com acquired in 2023. The SmartFile Host Key option uses the SmartFile SFTP host key and is provided for customers who have migrated from the SmartFile platform to the Files.com platform.

Custom Host Keys

The Custom Host Keys option lets you import your own SFTP host keys and is provided for customers who are migrating from other SFTP services, such as on-premises solutions, to the Files.com platform.

We recommend using the Files.com host key unless you have a business reason to choose another option.

Host keys must be generated securely and securely protected on the server side in order to fulfill their intended function, which is authentication of the server and protection against connection interception.

The Files.com Host Key was securely generated in a key signing ceremony in 2010 and has been securely protected on the Files.com network since its original generation. We are not aware of any security concerns related to the Files.com host key.

Files.com acquired ExaVault in 2021. We are not aware of any specific concerns related to the ExaVault host key, but we don't have enough information to guarantee that it was generated or stored securely prior to our acquisition.

Files.com acquired SmartFile in 2023. We are not aware of any specific concerns related to the SmartFile host key, but we don't have enough information to guarantee that it was generated or stored securely prior to our acquisition.

When importing a Custom Host Key from another vendor, you must take care to ensure that the other vendor has destroyed any copies of the host key after you have discontinued service at that vendor.

Using Custom Host Keys

You add each key in the Custom SFTP Host Keys section, then choose which of them your site presents to connecting clients.

A host key entry needs a name and the key text. Name it something that tells you where the key came from, because that name is how you identify the key when you select it later.

To present the keys, set the provider to Custom Host Keys in the SFTP Host Key section and select the keys you want to use. The selector shows each key's name, algorithm, and fingerprint.

You can enable one key per algorithm. Clients added over the years will support different key algorithms. Enabling one key for each algorithm lets all of them connect against a fingerprint they already trust.

A change to your site's active host keys takes effect within 5 minutes.

The Custom SFTP Host Keys section shows the SHA256 fingerprint of every key you have imported, so you can verify its integrity. To replace a key, edit it and paste the replacement key text.

Custom Host Key Format

Custom SFTP host keys must be in PEM formatExternal LinkThis link leads to an external website and will open in a new tab.

Files.com supports the following SFTP host key algorithms:

  • RSA
  • DSA
  • ECDSA
  • ed25519

RSA host keys in PEM format begin with -----BEGIN RSA PRIVATE KEY----- and end with -----END RSA PRIVATE KEY-----.

DSA host keys in PEM format begin with -----BEGIN DSA PRIVATE KEY----- and end with -----END DSA PRIVATE KEY-----.

ECDSA host keys in PEM format begin with -----BEGIN EC PRIVATE KEY----- and end with -----END EC PRIVATE KEY-----.

ed25519 host keys in PEM format begin with -----BEGIN OPENSSH PRIVATE KEY----- and end with -----END OPENSSH PRIVATE KEY-----.

Host keys that are protected by a passphrase, also called encrypted keys, are not supported. Files.com must read the host key automatically every time an SFTP client connects, and a key with a passphrase cannot be read without a person entering the passphrase. Remove the passphrase from the key before importing it.

Removing a Passphrase from a Host Key

The ssh-keygen tool, included with OpenSSH on Linux, macOS, and current versions of Windows, can remove the passphrase from a host key. Run the following command on the machine that holds the key file, entering the existing passphrase when prompted. The key file is rewritten in place without a passphrase.

ssh-keygen -p -N "" -m PEM -f /path/to/host-key.pem

For an ed25519 key, leave out the -m PEM option, because ssh-keygen stores ed25519 keys in the OpenSSH format shown above.

A key file without a passphrase can be read by anyone who can open the file, so treat it like a password. After importing the key into Files.com, delete any copies of the file that you no longer need.