Ways to protect FTP security: use SSL encryption

  

If users who have used FTP should know that FTP is transmitted in clear text, the security requirements are very high, otherwise it is easy to steal information, so The security issue about FTP is the focus of everyone's attention. How to protect it? In fact, you can use SSL encryption.

Creating an SSL Certificate

To use the SSL function of Serv-U, you need SSL certificate support. Although Serv-U has automatically generated an SSL certificate at the time of installation, this default generated SSL certificate is the same in all Serv-U servers and is very insecure, so we need to manually create a new SSL. certificate.

The author takes the Serv-U5.0 Chinese version as an example. In the “Serv-U Administrator” window, expand the “Local Server & Rarr; Settings” option, and then switch to “SSL Certificate”. ” tab, here I create a new SSL certificate.

First enter the IP address of the FTP server in the "Ordinary Name" column, and then the contents of other columns, such as email, organization and organization, fill in according to the user's situation, complete the SSL certificate tab page. After filling in all the content, click the “Apply” button below, and Serv-U will generate a new SSL certificate.

Enabling SSL function

Although a new SSL certificate has been created for the Serv-U server, by default, Serv-U does not have SSL enabled. To use this SSL certificate, First, you need to enable the SSL function of Serv-U.

The author here wants to enable the SSL function of the domain name "RTJ" in the Serv-U server. In the "Serv-U Admin" window, expand the “local server→ domain → RTJ” option, then find the "Security” drop-down list in the "Domain" management box on the right Option. Here Serv-U provides three options, respectively, "only rule FTP, no SSL /TLS process", "allow SSL /TLS and rule process", "only allow SSL /TLS process", default In this case, Serv-U uses "only rule FTP, no SSL/TLS process", so SSL encryption is not enabled. Here, the author selects the “SSL/TLS Process Only” option in the “Security” box, and then clicks the “Apply” button to enable the SSL function of the RTJ domain.

Note: After the SSL function is enabled, the default port number used by the Serv-U server is no longer "1", but "“990", this FTP user must pay attention to it, otherwise It will not be able to successfully connect to the Serv-U server.

Copyright © Windows knowledge All Rights Reserved