Post a reply

Before posting, please read how to report bug or request support effectively.

Bug reports without an attached log file are usually useless.

Options
Add an Attachment

If you do not want to add an Attachment to your Post, please leave the Fields blank.

(maximum 10 MB; please compress large files; only common media, archive, text and programming file formats are allowed)

Options

Topic review

gowap

[EN] Manually is a source of error / [FR] Manuellement est sources d'erreur

[EN] I understand your feedback, but it remains a manual comparison.
I'm talking about indicating in advance one or more FINGERPRINTs in the configuration window, which will be saved in the registry. The objective is not to see the "WARNING" window.
On my side, the configurations are previously pushed by GPO in the user register, so this memorization in the configuration would be a relevant solution.

[FR] Je comprend votre retour, mais cela reste une comparaison manuel.
Moi, je vous parles d'indiquer à l'avance un ou plusieurs FINGERPRINT dans la fenêtre de configuration, qui sera sauvé dans le registre. L'objectif est de ne pas voir la fenêtre "WARNING".
De mon coté, les configuration sont préalablement poussées par GPO dans le registre des utilisateurs, alors cette mémorisation dans la configuration serait une solution pertinente.
martin

Re: [EN] Server authentication / [FR] Authentification du serveur

You do not have to accept it arbitrarily. WinSCP shows you the fingerprint on the box. Compare it against a fingerprint of the actual public key.
Or you can copy the public key (or its fingerprint) to the clipboard and use Accept > Paste Key command:
https://winscp.net/eng/docs/message_host_key
gowap

[EN] Server authentication / [FR] Authentification du serveur

[EN] The configuration window to connect to an SFTP server without a password using a private key does not offer to load the server's public key file. However, this would ensure that the remote server is legitimate. Please add this feature so that you do not have to arbitrarily accept the proposed server when connecting.

[FR] La fenêtre de configuration pour se connecter à un serveur SFTP sans mot de passe en utilisant une clé privée ne propose pas le chargement du fichier de la clé publique du serveur. Cela permettrait toutefois de garantir que le serveur distant est légitime. Merci d'ajouter cette fonctionnalité afin de ne pas devoir accepter arbitrairement le serveur proposé lors de la connexion.