EFT Server Specifications

This topic is intended as a quick reference of EFT Server specifications. The information is provided in detail in the applicable procedures.

Item

Description

Server's Windows user account

The EFT Server service runs under a user account, which must have full administrative rights to the folder in which you install EFT Server. With administrative rights, the service can save all of your settings. If the service does not have administrative rights, you will lose settings and user accounts whenever you restart the EFT Server service, and you will need to reset permissions on the computer on which the EFT Server service is running. If you are using Active Directory, there are other considerations regarding permissions.

Protocols allowed

FTP/S (SSL/TLS), SFTP (SSH2), HTTP/S, and AS2 (Certain protocols require optional modules and/or  EFT Server Enterprise.)

Authentication types

GlobalSCAPE, AD/NTLM, LDAP, ODBC

Log formats

W3C, Microsoft IIS, and NCSA

SSL Certificate Key lengths supported

Key lengths supported: 1024, 2048, 3072, and 4096 bits

Server-created SSL certificates

x.509 base-64 standard DER encoded

Allowed OpenSSL ciphers

Name in Cipher List

OpenSSL Name

Enabled by default

AES 256 bit

AES256-SHA

Yes

Camellia 256 bit

CAMELLIA256-SHA

Yes

3DES 168 bit

DES-CBC3-SHA

Yes

AES 128 bit

AES128-SHA

Yes

IDEA 128 bit

IDEA-CBC-SHA

Yes

RC4 128 bit

RC4-MD5

Yes

Export (40-56 bit)

EXP

No

Allowed SSL versions

TLS 1.0, SSL 2.0, or SSL 3.0

  • EFT Server version 6.3 uses OpenSSL 0.9.8o; FIPS SSL is based on OpenSSL 0.9.7m

  • EFT Server version 6.2 uses OpenSSL 0.9.8l (L)

  • EFT Server version 6.1 and earlier use Open SSL 0.9.8a

Hashing algorithms supported

  • MD2

  • MD4

  • MD5

  • Haval

  • RIPE-MD

  • SHA-1

  • SHA-Double

  • Tiger

OpenPGP version

OpenPGP is a standard and has no version. EFT Server adheres to the OpenPGP standard and is RFC 2440 compliant.

FIPS

EFT Server supports public key lengths for RSA in FIPS SSL from 1024 to 4096 bits. The FIPS library used by EFT Server is certified with keys that are DSA (1024 bits only) or RSA (1024, 2048, and 4096).

PCI DSS

EFT Server facilitates compliance with PCI DSS 2.0.

SFTP

EFT Server supports SFTP versions 2, 3, 4, and 6. The outbound client defaults to version 4, and it is not configurable through the GUI. The EFT Server outbound client negotiates the SFTP version with the receiving server during session establishment. That is, if the receiving server only supports version 2, EFT Server will negotiate down and operate at version 2.

AS2 module

EFT Server uses /n software's IP*Works EDI Engine, in compliance with RFC4130

Maximum Capacity for EFT Server

Listed below are several EFT Server object types and the maximum number of each type (both theoretical maximum and tested maximum) that can be defined in EFT Server. Keep in mind that an excessive number of total objects displayed in the administration interface can affect the responsiveness of the interface.

EFT Server Object

Theoretical Maximum

Tested Maximum

Maximum number of Server Groups

32768

maximum not tested

Maximum number of Servers

32768

10+

Maximum number of Sites

2147483647

40+

Maximum number of Settings Templates

2147483647

maximum not tested

Maximum number of users per Server

2147483647

100,000

Maximum number of users per Site

2147483647

100,000

Maximum number of users per Settings Template

2147483647

100,000

Maximum number of users per Group

2147483647

100,000

Maximum number of administration accounts

2147483647

1,000

Maximum number of Permissions (on VFS tab)

2147483647

maximum not tested

Maximum number of Groups

2147483647

maximum not tested

Maximum number of Folders

2147483647

100,000

Maximum number of Event Rules

65536

4,000 Folder Monitor Event Rules

Maximum number of Commands

65536

maximum not tested

Maximum number of AWE tasks

65536

maximum not tested

Maximum number of Reports

65536

maximum not tested

Maximum number of simultaneous connections

65536

1,000

Note: Object type distribution for baseline and testing purposes was roughly 80% users, 10% Folder Monitor Event Rules, 5% other Event Rules, 2.5% AWE tasks, 2.5% other.