Choose FTP over TLS or Plain FTP and Understand the Security Difference

This article explains the FTP security choices QCSB exposes, why encrypted FTP over TLS is preferred when the server supports it, and when plain FTP may still be required by a legacy endpoint.

What you need to know

  • FTP over TLS encrypts the FTP session when supported. Plain FTP should be reserved for legacy endpoints where TLS cannot be used; SFTP is preferable when confidentiality is a requirement.

How to do it

  1. Open Storage Connections and create or edit the FTP connection.
  2. In Security, choose FTP over TLS when the FTP server supports TLS. This encrypts the FTP session and is the preferred current choice.
  3. Choose Plain FTP only when the legacy endpoint cannot use TLS and the risk is acceptable for that network/environment.
  4. Save or use Test Connection after changing the mode; a server that does not support the selected security mode will fail before the Workspace can use it.
  5. Verify a small listing/upload/download through a test Workspace before exposing the connection to production users.

Verify the result

  • Test Connection succeeds.
  • The displayed/usable root is exactly the intended root and no parent folder is reachable.
  • A normal authorized user can perform only the operations intended for that connection/Workspace role.

Troubleshooting

  • If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
  • Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.