EFT Server Specifications

This topic is intended as a quick reference of EFT Server specifications. The information is provided in detail in the applicable procedures.

Item

Description

Server's Windows user account

The EFT Server service runs under a user account, which must have full administrative rights to the folder in which you install EFT Server. With administrative rights, the service can save all of your settings. If the service does not have administrative rights, you will lose settings and user accounts whenever you restart the EFT Server service, and you will need to reset permissions on the computer on which the EFT Server service is running. If you are using Active Directory, there are other considerations regarding permissions.

Protocols allowed

FTP/S (SSL/TLS), SFTP (SSH2), HTTP/S, and AS2 (Certain protocols require optional modules and/or  EFT Server Enterprise.)

Authentication types

GlobalSCAPE, AD/NTLM, LDAP, ODBC

Log formats

W3C, Microsoft IIS, and NCSA

SSL Certificate Key lengths supported

Key lengths supported: 1024, 2048, 3072, and 4096 bits

Server-created SSL certificates

x.509 base-64 standard DER encoded

Allowed OpenSSL ciphers

Name in Cipher List

OpenSSL Name

Enabled by default

AES 256 bit

AES256-SHA

Yes

Camellia 256 bit

CAMELLIA256-SHA

Yes

3DES 168 bit

DES-CBC3-SHA

Yes

AES 128 bit

AES128-SHA

Yes

IDEA 128 bit

IDEA-CBC-SHA

Yes

RC4 128 bit

RC4-MD5

Yes

Export (40-56 bit)

EXP

No

Allowed SSL versions

TLS 1.0, SSL 2.0, or SSL 3.0; FIPS SSL is based on OpenSSL 0.9.7m; Standard SSL is based on OpenSSL 0.9.8i.

Hashing algorithms supported

  • MD2

  • MD4

  • MD 5

  • Haval

  • RIPE-MD

  • SHA-1

  • SHA-Double

  • Tiger

OpenPGP version

OpenPGP is a standard and has no version. EFT Server adheres to the OpenPGP standard and is RFC 2440 compliant.

FIPS

Supported public key lengths for RSA in FIPS SSL is from 1024 to 4096 bits. The FIPS library used by EFT Server is certified with keys that are DSA (1024 bits only) or RSA (1024, 2048, and 4096).

PCI DSS

EFT Server follows PCI DSS 1.2.