ChristianGfK

Comments

  • Combine this with Serv-U Gateway and you can also get the "turn it back on after reboot" functionality. Configure the same listener on more than one back-end Serv-U MFT servers that are configured to use the same Serv-U Gateway. Only one of them can actually use a specific IP+Port pair, the other will show a warning…
  • Yes, but why are you worried about exposing the login page over unencrypted HTTP, but at the same time consider unencrypted FTP unproblematic? Disabling unencrypted FTP is a Good Thing . Yes, FTPS de-facto limits you to Passive Mode and requires you to define a specific PASV port range so that you can drill some holes into…
  • You can achieve this by enforcing encrypted connections before login: Domain > Limits & Settings > Limits > Connection > Require secure connection before login > Yes Enabling this will cause connections to a regular HTTP listener to be redirected to a corresponding HTTPS listener. This is more of a side-effect, the real…
  • As others have pointed out here and in other requests, this has been possible for a long time. You can achieve this by enforcing encrypted connections before login: Domain > Limits & Settings > Limits > Connection > Require secure connection before login > Yes Enabling this will cause connections to a regular HTTP listener…
  • The HTTPS listeners do send HSTS headers. 
  • It has. You can achieve this by enforcing encrypted connections before login: Domain > Limits & Settings > Limits > Connection > Require secure connection before login > Yes Enabling this will cause connections to a regular HTTP listener to be redirected to a corresponding HTTPS listener. This will also disable plain,…
  • I just opened a support case about this in 2023... and of course, someone not only already wanted it, but wanted it in 2017.
  • You can achieve this by enforcing encrypted connections before login: Domain > Limits & Settings > Limits > Connection > Require secure connection before login > Yes Enabling this will cause connections to a regular HTTP listener to be redirected to a corresponding HTTPS listener. This will also disable plain, unencrypted…
  • Go into Domain Details -> Listeners and disable the relevant listeners. It will do exactly this. New sessions will no longer be able to connect, old sessions will remain until finished or terminated.
  • Serv-U already supports the rsa-sha2-512 and rsa-sha2-256 host key algorithms. You can check by going into the session list and looking at SFTP sessions. It is shown as "public key protocol". Combine that with ssh -o HostKeyAlgorithms=xyz and you can verify for yourself.
  • Your argument is full of contradictions. Indeed, the world is finally moving to a secure nature. Help move it. Disable unencrypted connections! TLS is valuable even for public files. TLS guarantees that no-one is impersonating your server, it guarantees that files are not tampered with in transit, and it protects the…
  • Please allow the same for MODE Z. The CPU usage from decompressing gigabytes of data makes Serv-U unresponsive.
  • It has a kind-of roadmap: thwack.solarwinds.com/.../wwwo