SFTP Host Key
SFTP, and its underlying protocol SSH, have a concept of Host Keys, which is a way for clients to confirm using secure cryptography that they are connecting to the correct server (host).
Ordinarily in SSH, each host will use a unique host key that is generated by and associated with each host.
In a business-to-business service such as SFTP, one host key is used persistently over time so clients always recognize the service when connecting.
Files.com Default SFTP Host Keys
Files.com presents an RSA host key to all SFTP clients that support RSA. For clients that do not support RSA but do support ED25519, Files.com presents an ED25519 host key instead. Clients that support both key types always receive the RSA key, regardless of their stated preference order.
This ensures that our adding support for ED25519 does not cause host key mismatch errors for any connections already using the RSA key.
RSA Host Key
Files.com uses a 4096-bit RSA SSH host key. The host key itself (in OpenSSH format) and fingerprints in three different formats are provided below. Use whichever format is required by your SFTP app.
OpenSSH host key: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCD+pdvc7zeWkcDuyo4k7fca+BVqSSnbGteq2fcquo+jbN9rXySnlbHyAZsxwXIxn/TMWFQCgD619TbdMQ2F4x0tC/UfrNiF0tCQ0UZNlOuQz6G2a0QBzMRgeugGqbFOHHQTaOcgMJoW0ai8vbpHlGMybqcjQg+MWC8fNl4WcX9Ruze713WhcTIbrA4P7iqlyjFkiaQMX642mO0/RboME/4TdyNg7w0bxJaLifiIGtStZ5cRWSW8nxr/PEdQPeSg/2HshyUFJx6GD7ej3NeFsDuYCYFdBXGpZ/Tp6i2mIC/NoVO+3Hz7Pw6JA+H3tEy8U9zqSwPk9RIGlKoWTtZvo9xcBwCFIPyMymU83gfioZYZN4uK196oX/2sspMUIOTUlA4eeIdmbDbK0w1QYGr1bOk/5bKgxybDx4m7FsY3NDylZKDmS1SMVPg1C/GYVdpheOHZpzH5f8qT34ZRFGmktIhRqD+cSiNdcDMDebRBeFG/mCIVSNnoEiDKjKqH/+dpdiJHlTDSH1QCg/d+HSX4eEVG0AudIeSELjaJg2V0kVbk9gF28G0BzQ6NxGm9d7hZD61BfjcuxgRr1bqx6uEip0WrNTinNEIleB1L6M5BUapeICBe+F0Kte+qBYrVENWJoai9V9l/IuBvYWIWkMf0MsuGeiQi2IOvEMfwrD9jBlWqw==
SHA256 fingerprint: JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw
SHA1 fingerprint: go2g72JG1emRzP54QtFmFrE0DTg
SHA1 hex digest: 82:8d:a0:ef:62:46:d5:e9:91:cc:fe:78:42:d1:66:16:b1:34:0d:38
MD5 fingerprint: 79:e1:fc:1c:8d:d7:95:25:84:c5:70:16:4d:07:e0:c5
Please refer to the documentation for your specific SFTP client for exact details about how to use a host key fingerprint.
For example, WinSCP provides host key fingerprint capability via its -hostkey option. When using the WinSCP command line, you can specify:
-hostkey="ssh-rsa 4096 JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw"
When using the WinSCP Script Command option, you can specify:
open sftp://user:XXXXX@[subdomain].files.com -timeout=30 -privatekey=C:\path\to\my-private.key -hostkey="ssh-rsa 4096 JvS7SrgY9QfsC2otdG0TGo0aWcvvieGg1R2Vx8/5VSw"
ED25519 Host Key
Files.com uses an ED25519 SSH host key for clients that do not support RSA. This key is only presented when the connecting client advertises no support for RSA. Clients that support both RSA and ED25519 always receive the RSA key instead, regardless of client preference order. The host key itself (in OpenSSH format) and fingerprints in multiple formats are provided below.
OpenSSH host key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOH0/3culh5tgsVyIsH5gu8cCpKmoimc2w+cTm3CHHHo
SHA256 fingerprint: 1mU7ovnpCSl9X523W40erKu1JipY4LzMb5co4I4+N6A
SHA1 fingerprint: aFlJi9yw2UkcJHsyQ0+S+iFdgLM
SHA1 hex digest: 68:59:49:8b:dc:b0:d9:49:1c:24:7b:32:43:4f:92:fa:21:5d:80:b3
MD5 fingerprint: 74:d6:34:42:7e:d6:4e:c3:41:bc:39:7c:00:51:ab:6a
ExaVault SFTP Host Key Fingerprints
For sites configured to use the ExaVault host key, use the appropriate format listed here for your SFTP client to check the host key.
OpenSSH Host key ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDk7ZSzE4vqFaZoLCpErMNFz81iT+EIXifOT+TYwPozcq16lOWUAa2EyG/xSAK5l5otYG8fdTt8H8HeDYKaxWo4vQ2bLNuiVUlGTUAUxjxhAZGJzed/gfID/RnOStnabZIT9ElOObv5U0ZKgDrvsbjbB8Y51XxfwaqqXtIq/WIIstpX4sjTOpM3YmuY8OLbd/p0SQcjTg5PFlIgQuRX8hOo811lQzbp9t2QsUEhMcKGAPsRCM/nbn3p8/JD0nc3PtjKolrLfsBaR9aDwkV/b9SprpcBXrVvmHIhg5qjt88r7QW0f8MJiYkuQsG80g7VtlKf+OUGTR93+hNrXSmZp5F3
SHA256 fingerprint: BafxoY7Md78+Iwj2Chcv/kRIO2ZH2EpNuL5H42WiDJY
SHA1 fingerprint: KfsbIcTkzl5tFqH30AqNHeJDq2s
SHA1 hex digest: 29:fb:1b:21:c4:e4:ce:5e:6d:16:a1:f7:d0:0a:8d:1d:e2:43:ab:6b
MD5 fingerprint: 0e:ce:3e:a2:be:7e:45:1f:0b:dd:c5:41:e0:96:c9:b7
SmartFile SFTP Host Key Fingerprints
For sites configured to use the SmartFile host key, use the appropriate format listed here for your SFTP client to check the host key.
SHA256 fingerprint 1: npYmj8dqQjp3XqH1VVlOSjW2CbcSrt43bXDMzNXkKxs
MD5 fingerprint 1: 8e:15:c8:81:c2:1f:23:a2:64:82:76:40:8c:12:58:40
SHA256 fingerprint 2: g+kpwxVcKZAqFFbwpG/c44yACwMzzEENQlKN4EzQRO4
MD5 fingerprint 2: b8:65:5e:f5:e0:9f:0d:83:9e:3d:da:b0:fb:12:b0:68
Customizing the SFTP Host Key
When migrating SFTP services from another vendor or an on-premises environment to Files.com, you can continue using any host key that is already in use.
Files.com lets you customize your SFTP host key so that migrating existing SFTP services to the Files.com platform is smooth.
You can configure your SFTP host key in the SFTP Host Key section of the Encryption settings of your Files.com site.
The available Host Key Provider options are:
- Files.com Host Key (default)
- ExaVault Host Key
- SmartFile Host Key
- Custom Host Keys
Files.com Host Key
The Files.com Host Key option uses the Files.com SFTP host key described above. This is the default.
ExaVault Host Key
ExaVault is another Managed File Transfer service that Files.com acquired in 2021. The ExaVault Host Key option uses the ExaVault SFTP host key and is provided for customers who have migrated from the ExaVault platform to the Files.com platform.
As of mid-2023, the ExaVault host key was only available in our USA region. We expect to bring the ExaVault host key to all regions very soon.
SmartFile Host Key
SmartFile is another Managed File Transfer service that Files.com acquired in 2023. The SmartFile Host Key option uses the SmartFile SFTP host key and is provided for customers who have migrated from the SmartFile platform to the Files.com platform.
Custom Host Keys
The Custom Host Keys option lets you import your own SFTP host keys and is provided for customers who are migrating from other SFTP services, such as on-premises solutions, to the Files.com platform.
Custom host keys require dedicated IP addresses. Your site receives a pair when you set up its Primary Custom Domain. An additional Custom Domain needs its own dedicated addresses before you can assign host keys specifically to it. Custom domains and dedicated IP addresses are available on the Power and Enterprise plans.
The SFTP server presents its host key while establishing the SSH connection, before the user signs in. A dedicated IP address lets Files.com identify which site's or domain's host keys to present at that stage. Configure clients to use the custom domain that points to the corresponding dedicated addresses.
Security Notes Related to Host Keys
We recommend using the Files.com host key unless you have a business reason to choose another option.
Generate host keys securely and keep their private keys confidential so clients can rely on the host key fingerprint to identify the server.
The Files.com Host Key was securely generated in a key signing ceremony in 2010 and has been securely protected on the Files.com network since its original generation. We are not aware of any security concerns related to the Files.com host key.
Files.com acquired ExaVault in 2021. We are not aware of any specific concerns related to the ExaVault host key, but we don't have enough information to guarantee that it was generated or stored securely prior to our acquisition.
Files.com acquired SmartFile in 2023. We are not aware of any specific concerns related to the SmartFile host key, but we don't have enough information to guarantee that it was generated or stored securely prior to our acquisition.
When importing a Custom Host Key from another vendor, you must take care to ensure that the other vendor has destroyed any copies of the host key after you have discontinued service at that vendor.
Using Custom Host Keys
Site Administrators add each key in the Custom SFTP Host Keys section, then choose whether it serves the site or one additional Custom Domain. Use domain-specific keys when consolidating SFTP services whose clients already trust different host keys. Each domain can keep its own server identity while the users and files are managed in one site.
A host key entry needs a name and the private key text. Name it something that identifies the service it belongs to. The table shows each key's algorithm, SHA256 fingerprint, and Custom Domain assignment, displayed as Site-wide or the domain name.
Site-Wide Keys
When adding or editing the key, leave the Custom Domain field set to Site-wide if it is shown. To present the key, set the provider to Custom Host Keys in the SFTP Host Key section and select the keys you want to use. The selector shows each key's name, algorithm, and fingerprint, and lists only site-wide keys.
You can enable one site-wide key per algorithm. Clients added over the years may support different algorithms, so select the keys those clients can use and already trust.
Keys for an Additional Custom Domain
For an SFTP migration, configure the additional domain as a Site Alias and allocate its dedicated IP addresses. Update its CNAME using the target displayed for that domain before directing clients to it.
The Custom Domain field appears on the Add and Edit Custom SFTP Host Key forms once at least one additional domain on the site has dedicated addresses. Only domains with dedicated addresses are available. Choose the domain and turn on Active to use the key for that domain. Domain keys are managed from this form, independently of the site-wide SFTP Host Key selector.
Each domain can have one active key per algorithm. For example, two domains can each have a different active RSA key, and the site can also have its own active RSA key. Activating a key for one domain does not replace the active keys for another domain or for the site.
Changing or Removing a Key
A key selected in the site-wide SFTP Host Key setting must be deselected there before it can be assigned to a domain. To move a domain key back to site-wide use, select Site-wide on its edit form, save it, then select it in the site's SFTP Host Key setting. Removing the domain assignment leaves the key inactive until you select it there.
An active key cannot be deleted. Deselect a site-wide key in the site's SFTP Host Key setting, or turn off Active on a domain key's edit form, before deleting it. If another key of the same algorithm is active for the intended site or domain, deactivate that key before activating its replacement.
To replace the private key, edit the entry and paste the replacement key text. Changing a key or its domain assignment can cause connection warnings or failures for clients that trust the previous fingerprint. Verify the displayed SHA256 fingerprint against the expected key for each hostname and coordinate any client trust changes before switching keys. A change to active host keys takes effect within 5 minutes.
Custom Host Key Format
Custom SFTP host keys must be in PEM format.
Files.com supports the following SFTP host key algorithms:
- RSA
- DSA
- ECDSA
- ed25519
RSA host keys in PEM format begin with -----BEGIN RSA PRIVATE KEY----- and end with -----END RSA PRIVATE KEY-----.
DSA host keys in PEM format begin with -----BEGIN DSA PRIVATE KEY----- and end with -----END DSA PRIVATE KEY-----.
ECDSA host keys in PEM format begin with -----BEGIN EC PRIVATE KEY----- and end with -----END EC PRIVATE KEY-----.
ed25519 host keys in PEM format begin with -----BEGIN OPENSSH PRIVATE KEY----- and end with -----END OPENSSH PRIVATE KEY-----.
Host keys that are protected by a passphrase, also called encrypted keys, are not supported. Files.com must read the host key automatically every time an SFTP client connects, and a key with a passphrase cannot be read without a person entering the passphrase. Remove the passphrase from the key before importing it.
Removing a Passphrase from a Host Key
The ssh-keygen tool, included with OpenSSH on Linux, macOS, and current versions of Windows, can remove the passphrase from a host key. Run the following command on the machine that holds the key file, entering the existing passphrase when prompted. The key file is rewritten in place without a passphrase.
ssh-keygen -p -N "" -m PEM -f /path/to/host-key.pem
For an ed25519 key, leave out the -m PEM option, because ssh-keygen stores ed25519 keys in the OpenSSH format shown above.
A key file without a passphrase can be read by anyone who can open the file, so treat it like a password. After importing the key into Files.com, delete any copies of the file that you no longer need.