Articles from general category

SFTPPlus 3.15.0 Release

Mon 24 October 2016 | general release

We are pleased to announce the latest release of SFTPPlus, version 3.15.0.

The release was done to address an intercompatiblity issue of SFTPPlus FTPS server-side when interacting with the WinSCP FTPS client.

Beside fixing the above mentioned issue, starting with this release you can configure the FTP/FTPS services to not advertise the product name and version as port of the FTP banner / welcome message.

You can check the full release notes.

• • •

SFTPPlus 3.14.0 Release

Tue 18 October 2016 | general release

We are pleased to announce the latest release of SFTPPlus, version 3.14.0.

It adds support for the Next CRL Publish extension used to schedule the automatic refresh of a CRL.

You can check the full release notes.

• • •

SFTPPlus 3.13.0 Release

Wed 14 September 2016 | general release

We are pleased to announce the latest release of SFTPPlus, version 3.13.0.

This release adds support for authenticating account stored in LDAP

Beside many other small improvements, in this release we have added support for FTPS client-side functionality, implicit and explicit. This is in a preview state and is not production ready. We are working on testing the client-side functionality with the major implementation to be production ready for the next release.

Here is the list of the most important defects fixed in this release:

  • The user account is now correctly registered in the Account Activity Report.
  • On Solaris 10 is it now possible to authenticate FTPS clients using an SSL/X.509 certificate generated by latest CAs and using UTF8STRING. In previous releases, Solaris 10 was expecting that UTF-8 values are stored in BMPSTRING fields.

You can also check the full release notes.

• • •

SFTPPlus 3.12.0 Release

Mon 01 August 2016 | general release

We are pleased to announce the latest release of SFTPPlus, version 3.12.0.

This release adds a couple of security related functionalities and security related defect fixes.

Here is the list with the main new features:

  • Support was added for validating certificate revocation lists (CRL) based on the distribution points extension advertised by the peer's certificate.
  • It is now possible to use the fips configuration value in the ssh_cipher_list configuration option to allow using only FIPS 140-2 compliant ciphers and algorithms for the SSH based services.
  • Accounts authenticated using the HTTP authentication method can now be configured to be associated with any group defined in SFTPPlus. In previous implementation they were always associated with the default group.
  • You can now authenticate legacy SFTPPlus WebAdmin accounts as operating system accounts using the "User Alias" configuration option defined by the WebAdmin.

Here is the list of the most important defects fixed in this release:

  • Certificates signed by unknown certificate authorities are now rejected right away, without being first checked for revocation.
  • Home folder path configuration can no longer be defined with empty values. This prevents accidental configuration in which the account is given access to the application's installation folder.
  • Home folder path configuration is now enforced to absolute paths. This prevents accidental configuration in which the account is given access to the application's installation folder.
  • An internal server error is no longer generated when an invalid path is configured as a home folder.
  • An internal server error is no longer emitted when a response from the Local Manager is produced after the Local Manager page was closed or refreshed.
  • Transfers will no longer fail shortly after being started or resumed when the source locations fails. The transfers enter the suspended stated and will automatically resume once the source is available.
  • Rotating files base on size will now keep all rotated files when rotate_count is set to 0.
  • The HTTP/HTTPS service will now request the web browser to download files with unknown mime types (extensions) rather than trying to display them as HTML files.

You can also check the full release notes.

• • •

SFTPPlus 3.11.0 Release

Fri 10 June 2016 | general release

We are pleased to announce the latest release of SFTPPlus, version 3.11.0.

This release adds SUSE Linux Enterprise Server (SLES) 10 to the list of supported SUSE versions.

The support for certificate revocation list was extended in this version to support loading CRLs over HTTP and supporting multiple CRLs for a single service.

Here is the list with the main new features:

  • It is now possible to configure a list of ciphers used by the SSH based services. You can now configure the accepted symmetric encryption, key exchange and MAC algorithms. [sftp][scp]
  • It is now possible to load CRLs from local filesystem in both PEM and DER format. Previously only the PEM format was supported.

Here is the list of the most important defects fixed in this release:

  • Database event handlers will now resume once the associated database becomes available again.
  • The state of a transfer is now correctly reported as stopped, when the transfer was stopped while in the stalled state.

You can also check the full release notes.

• • •