← SFTP: transfers and batch operations
01 / 6 · 40 MIN

Transport and server trust

Distinguish protocol, server identity, account authentication, and subsystem startup.

Concept and mechanism

SFTP transfers files over SSH. Changing the port of an FTP-over-TLS integration does not establish compatibility: client and endpoint must implement the agreed protocol. Map connection, negotiation, host trust, account authentication, and subsystem startup. Each stage can fail differently. If logs already confirm authentication, failure to start SFTP points to later configuration or availability rather than automatically justifying a new password. The scp command also needs version awareness: since OpenSSH 9.0 it uses SFTP by default, so scripts relying on remote-shell behavior need review. Establish the protocol actually used before changing path handling or access policy.

Guided application

The server key supports checking the expected identity when a trusted reference exists. ssh-keyscan collects the offered key; repeating collection is not independent confirmation. Compare its fingerprint through an agreed authenticated channel. In a fictional migration, the operator account accepts a new key while the scheduler retains another reference. Confirm the authorized change and update the correct context. accept-new does not silently accept changes to known keys. Avoid deleting the entire inventory to remove one alert. Recovery should demonstrate connection to the expected partner and functioning scheduled execution, with evidence supporting change acceptance or rollback.

IN PRACTICE

A successful manual session does not update scheduler-account trust.

Common pitfalls

Port as protocol; collection as authentication; user key as host identity; shell as SFTP.

Related topics: Permissions and isolation · Batch and observable failures · File publication and resumption

Take this idea with you

Locate the failed stage and validate identity in the actual execution context.

Create account

Reference: RFC 4253 SSH transport architecture · DR SFTP 2026-09; selected OpenSSH client, server and extension behavior