Configure an SFTP Export Destination in QC Backup Manager
SFTP is QCBM's preferred remote-server export option when your storage server supports SSH. The destination stores the connection details QCBM needs to upload a Recovery Package and requires an independently verified SSH host-key SHA-1 fingerprint before the connection is considered configured.
Off-site export requires Pro, Max, or All Access. Pro can use one off-site destination; Max and All Access can manage multiple destinations.
Before You Configure SFTP
Obtain the SFTP host name, port, username, password, remote folder, and the server's SSH host-key SHA-1 fingerprint from the server owner or hosting provider. Do not copy a fingerprint from an unexpected connection prompt and assume it is trustworthy; verify it through a separate trusted channel.
The PHP ssh2 extension must be available on the Joomla server. QCBM stops the SFTP connection if it cannot read the server fingerprint, if no trusted fingerprint is saved, or if the presented fingerprint does not match the saved value.
Create the Destination
- Open Settings and find Export Destinations.
- Choose Add New.
- Enter a descriptive Destination name.
- Set Destination type to SFTP / SSH.
- Enter the Remote host, Port, Username, Password, and Remote folder. The normal SFTP port is 22 unless your server uses another port.
- Enter the independently verified SFTP host-key SHA-1 fingerprint.
- Adjust Timeout seconds only when the remote environment needs a value other than the default.
- Optionally add a non-secret credential label or operational note.
- Enable the destination when it is ready for testing. Set it as the default only if it should receive Export to Default and Profile auto-exports.
- Save the destination.
Why the Host-Key Fingerprint Matters
QCBM reads the SHA-1 fingerprint presented by the SSH server before password authentication. It compares that fingerprint with the value saved in the destination by using an exact, normalized comparison.
If the values differ, QCBM stops before authentication and reports both the expected and presented fingerprints. Treat a mismatch as a security or configuration problem. Do not replace the saved fingerprint until you independently confirm that the SFTP server's host key was intentionally changed.
Test the SFTP Destination
From the Export Destinations list, click Test. QCBM connects using SFTP, verifies the host key, authenticates, makes sure the configured remote folder is available, uploads a small temporary test file, checks the remote file size, and removes the test file.
A passing test confirms that the saved connection worked at that moment. It does not guarantee future quota, network availability, credentials, or server permissions.
Verify with a Real Backup Export
After the destination test passes, manually export one completed Backup Set. QCBM rechecks the Backup Set's package health before the transfer and records the export separately from the local backup result.
Confirm the export succeeds before relying on automatic Profile export. Keep the valid local Backup Set until you know the remote copy is where you expect it to be.
If SFTP Stops Working Later
Re-test the destination and read the exact failure. Common causes include a changed SSH host key, changed password, removed account access, a remote-folder permission change, firewall/network failure, or a missing PHP ssh2 capability.
If the host key changed legitimately, obtain the new fingerprint independently before saving it. A remote-export problem does not automatically invalidate an already verified local Recovery Package.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.