Configuring SSL

Specify SSL versions and ciphers before enabling SSL connections. SSL connections can be enabled at the Site, User Setting Level, and per user.

To configure SSL

  1. In the left pane, click the Server.

  2. In the right pane, click the Security tab.

  3. In the SSL Compatibility area, specify the version to use:

  4. Specify one or more Ciphers to use, or manually specify the ciphers. At least one cipher must be specified. If more than one approved cipher is specified, and the connecting client has in its list one or more ciphers that are also on EFT Server’s approved list, EFT Server will select and use the cipher based on ordering (priority) shown in the list box.

  5. Only advanced users should manually specify ciphers.

  6. In the Select from list box, check the box of ciphers to use and clear the check box for those ciphers that you do not want to use.

  7. Click the Priority arrows to arrange the ciphers in top-down priority.

  8. In the Protocol Specific area, check the Allow Clear Command Channel (CCC) for FTPS connections and/or Allow unprotected data channel (PROT C) for FTPS connections, as needed. Users that attempt CCC or Prot-C must receive the appropriate FTP error code if not permitted by the Server. The client must then retry using protected command or data channels to connect.

  9. Click Apply to save the changes to EFT Server.

 

  • SSL Cipher and Version allowed settings affect ALL Sites on the Server.

  • PCI DSS requirements mandate use of 128-bit or higher ciphers, and SSLv3, TLS or greater.

  • A Certificate Authority (CA)-signed certificate establishes your validity better than a self-signed certificate.