SFTP Requirements and Authentication Choices
This article explains the Pro+ SFTP connector, SSH/SFTP server requirements, exact roots, password vs private-key authentication, optional passphrases, and QCSB host-key protection.
Choose the authentication method
| Area | What QCSB needs |
|---|---|
| Password | Host, port, username, password, exact root. Appropriate when the SFTP server permits password authentication. |
| Private key | Host, port, username, private key, optional passphrase, exact root. Appropriate when the server requires key authentication. |
| Host-key trust | Independent of user authentication. QCSB records/verifies the server fingerprint and blocks unexpected changes. |
Minimum checks before saving
- The SFTP account can list the exact root.
- Write/delete permission exists only where required by the Workspace role.
- The host fingerprint is expected.
- Subdirectory access is intentional.
Verify the result
- Test Connection succeeds.
- The displayed/usable root is exactly the intended root and no parent folder is reachable.
- A normal authorized user can perform only the operations intended for that connection/Workspace role.
Troubleshooting
- If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.