SSL FTP
Hello everyoneI have a windows server 2003 that currently runs iis and hosts an ftp site. the site has several virtual directories all setup with individual user names and passwords.One of our vendors requires eitherSecure FTP (SFTP)or FTP over SSL (FTPS).With a default installation of iis and ftp site configured with usernames and passwords do i meet one of those requirements?If not which security config is easier to install and maintain?
September 18th, 2008 4:41pm
Keith Burns said:
With a default installation of iis and ftp site configured with usernames and passwords do i meet one of those requirements? No.Your configuration will result in transmitting usernames and passwords in clear text over the Internet, which is exactly what your customer is trying to circumvent. The configuration is not a security best practice, since the usernames and passwords can be capturedusing a man in the middle attack.You cannot configure FTPS or SFTP with Internet Information Services (IIS) 6 in Windows Server 2003 or Windows Server 2003 R2.As an alternative you can install the FTP7 package on a Windows Server 2008 server or install a 3rd party FTP Server on your Windows Server 2003 box, that supports FTPS or SFTP.Download FTP7 for Windows Server 2008 here.
Free Windows Admin Tool Kit Click here and download it now
September 18th, 2008 7:31pm


