Understand SFTP Host-Key Trust and Changed-Key Blocking
This article explains first-use host-key recording for saved SFTP connections, why a later host-key change is blocked as a security event, and how to investigate legitimate server migrations before trusting a new key.
What you need to know
- SFTP records the server host-key fingerprint when trust is established and blocks a changed/untrusted fingerprint instead of silently accepting a potentially different server.
Host-key states
| Situation | QCSB behavior |
|---|---|
| First trusted use | QCSB records the SFTP server host-key fingerprint after the connection is deliberately verified/trusted. |
| Later connection, same key | The fingerprint matches and QCSB can continue with normal authentication/root checks. |
| Later connection, changed key | QCSB blocks the connection as a security event instead of silently trusting the new server identity. |
If the fingerprint changes legitimately
- Stop retrying the connection.
- Verify with the hosting/server administrator that the SFTP host key changed because of an intentional migration/rebuild/key rotation.
- Obtain the expected new fingerprint through a separate trusted channel.
- Only after independent verification should the stored trust be deliberately updated/re-established.
- Run Test Connection again and confirm the exact root before returning the connection to production.
Verify the result
- Test Connection succeeds.
- The displayed/usable root is exactly the intended root and no parent folder is reachable.
- A normal authorized user can perform only the operations intended for that connection/Workspace role.
Troubleshooting
- If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.