Skip to content
  • There are no suggestions because the search field is empty.

How To: Harden SFTP settings in Titan

Question

How can I ensure my SFTP settings which include Ciphers/MACs/Kexes are as secure as possible?

Reasoning

I would like to minimize the risk of having a security issue in my organization by configuring SFTP in Titan to have the recommended settings.

Answer

You have the option to enable/disable ciphers/macs/kexes to ensure you have the most secure setting on your environment.

Steps
  1. Login to the admin portal
  2. Navigate to the server instance in question.
  3. Go to the Services section and click on the SSH/SFTP tab.
 

A screenshot of a computerDescription automatically generated

Scroll down to the “Cipher Preferences”, “Key Exchange (Kex) Preference” and “MAC Preferences”.

A screenshot of a computerDescription automatically generated

Apply the recommended settings as seen in the table below:

 

Ciphers

MACs

KEXes

AES256-CTR

AES256-gcm

ECDH-SHA2-Curve25519

AES192-CTR

AES128-gcm

Curve25519-SHA256@libssh.org

Twofish256-CTR

Chacha20-Poly1305@openssh.com

Curve448-SHA512@libssh.org

Twofish192-CTR

HMAC-SHA2-512-etm@openssh.com

Diffie-Hellman-Group15-SHA512

AES128-CTR

HMAC-SHA2-256-etm@openssh.com

Diffie-Hellman-Group16-SHA512

Twofish128-CTR

 

Diffie-Hellman-Group17-SHA512

AES256-gcm@openssh.com  

Diffie-Hellman-Group18-SHA512

AES128-gcm@openssh.com  

 

AES256-gcm

 

 

AES128-gcm

 

 

 

Enable the recommended settings from above and disable everything else by clicking on the checkbox next to each algorithm
 
When done, click on apply.

 

 
 

Need More Help? We’ve Got You Covered.

If you didn’t find what you were looking for, our support team is here to help. Submit a ticket and one of our experts will follow up shortly.