Differences

This shows you the differences between the selected revisions of the page.

2009-03-04 2009-03-05
control and data channel encryption (martin) certificate (martin)
Line 17: Line 17:
In Implicit Mode, the entire FTPS session (both control and data channels) is unconditionally encrypted. In Implicit Mode, the entire FTPS session (both control and data channels) is unconditionally encrypted.
-===== SSL Certificates =====+===== [[certificate]] SSL Certificates =====
Much like HTTPS, but unlike [[ssh|SSH]], FTPS servers must provide a public key certificate. This certificate must be signed by a certificate authority. Much like HTTPS, but unlike [[ssh|SSH]], FTPS servers must provide a public key certificate. This certificate must be signed by a certificate authority.
If it is not, WinSCP will generate a warning stating that the certificate is not valid. Whether or not to trust such certificate is your choice. If you are connecting within a company network, you might feel that all the network users are on the same side and spoofing attacks are unlikely, so you might choose to trust the certificate without checking it. If you are connecting across a hostile network (such as the Internet), you should check with your system administrator, perhaps by telephone or in person. If it is not, WinSCP will generate a warning stating that the certificate is not valid. Whether or not to trust such certificate is your choice. If you are connecting within a company network, you might feel that all the network users are on the same side and spoofing attacks are unlikely, so you might choose to trust the certificate without checking it. If you are connecting across a hostile network (such as the Internet), you should check with your system administrator, perhaps by telephone or in person.

Last modified: by martin