[EN] Server authentication / [FR] Authentification du serveur

Advertisement

gowap
Joined:
Posts:
5
Location:
France

[EN] Server authentication / [FR] Authentification du serveur

[EN] The configuration window to connect to an SFTP server without a password using a private key does not offer to load the server's public key file. However, this would ensure that the remote server is legitimate. Please add this feature so that you do not have to arbitrarily accept the proposed server when connecting.

[FR] La fenêtre de configuration pour se connecter à un serveur SFTP sans mot de passe en utilisant une clé privée ne propose pas le chargement du fichier de la clé publique du serveur. Cela permettrait toutefois de garantir que le serveur distant est légitime. Merci d'ajouter cette fonctionnalité afin de ne pas devoir accepter arbitrairement le serveur proposé lors de la connexion.

Reply with quote

Advertisement

martin◆
Site Admin
martin avatar
Joined:
Posts:
43,035
Location:
Prague, Czechia

Re: [EN] Server authentication / [FR] Authentification du serveur

You do not have to accept it arbitrarily. WinSCP shows you the fingerprint on the box. Compare it against a fingerprint of the actual public key.
Or you can copy the public key (or its fingerprint) to the clipboard and use Accept > Paste Key command:
https://winscp.net/eng/docs/message_host_key

Reply with quote

gowap
Joined:
Posts:
5
Location:
France

[EN] Manually is a source of error / [FR] Manuellement est sources d'erreur

[EN] I understand your feedback, but it remains a manual comparison.
I'm talking about indicating in advance one or more FINGERPRINTs in the configuration window, which will be saved in the registry. The objective is not to see the "WARNING" window.
On my side, the configurations are previously pushed by GPO in the user register, so this memorization in the configuration would be a relevant solution.

[FR] Je comprend votre retour, mais cela reste une comparaison manuel.
Moi, je vous parles d'indiquer à l'avance un ou plusieurs FINGERPRINT dans la fenêtre de configuration, qui sera sauvé dans le registre. L'objectif est de ne pas voir la fenêtre "WARNING".
De mon coté, les configuration sont préalablement poussées par GPO dans le registre des utilisateurs, alors cette mémorisation dans la configuration serait une solution pertinente.

Reply with quote

Advertisement

You can post new topics in this forum