SFTPPlus

Secure file transfer using Open Standards (SSH, SFTP, FTPS, HTTP, PGP etc)
             plus additional audit & automation
for enterprise strength usage

         


SFTPPlus has been developed in close co-operation with a major insurance company to provide additional audit and management to Open Standard products for SFTP, FTPS & HTTPS in order to meet regulatory and corporate compliance requirements. It is a cost effective solution that may be installed at one side of the data transfer without being tied to any proprietary protocol. It is designed for use in most enterprise environments and to be flexible & adaptable to suit an unlimited range of needs for secure file transfer internally and externally.   

 

SFTPPlus features/benefits/requirements etc  - further details on request

This is only intended as a quick checklist for initial guidance.

Features/Benefits/Requirements   SFTPPlus
   X = included
Availability and compatibility  
Server edition X
Client edition X
Client/server transfers X
Supports other clients/servers X
 
Transfers  
Fully automated X
Scheduling X
drag 'n' drop X
monitor an 'inbox' directory X
wait for a triggering event X
Email Notification X
OS Specific Notifies X
Client Send X
Client Receive X
single & multiple destinations X
Directory transfers X
 
Encryption & protocols  
AES, 3DES, Blowfish etc X
Proprietary protocol  
SSH/SSH2/SFTP support X
FTPS (FTP over SSL) support X
HTTPS (HTTP over SSL) support X
PGP support X
MD5 checksum X
 
Retries  
by number of retries X
by time X
Guaranteed delivery X
Checkpoint Restart X
Recoverable Work Queue X
 
Control  
Throttling of Transfers  
Compression X
File to File X
Command Line X
automated pre processing X
automated post processing X
automated response processing X
Time stamp X
API X
TCP/IP X
 
 
Administration  
Centralised administration  X
Separate user database X
Flexible reports - see below also  X
 
Audit  
Notifications inc SMTP X
Logs to event logs X
Logs to database X
SNMP X
Automatic archive X
 
Authentication - see below for additional detail
Native authentication X
Active Directory X
Database for authentication X
Cached Passwords X
Public/private key X
 
Platform Support  
Windows X
UNIX (Solaris Sparc, Solaris x86, AIX, HP-UX)  X
Unix - Tru64 X
Linux (Intel) X
Linux - PPC/iSeries X
Linux - Sparc X
Linux - Alpha X
Linux - 390 tbc
OS/390 (z/OS) X
AS/400 (iSeries) in development
Mac OSX in development
OpenVMS in development
Tandem (non-stop, NonStop) in development
HP-UX Itanium X

 
Trial, Implementation & long term Support  
Email & telephone during trial X - free
On-site during trial X
Email & telephone during implementation X - free
On-site during implementation X
Email & telephone - long term - with support package X
On-site - long term X
Worldwide coverage X
 

FIPS 140-2 Certification.

We have started the process of obtaining certification for the SFTPPlus Crypto Module under FIPS 140-2 and expect to obtain certification during 2007 for Windows, Unix and Linux.

However it may help in the short term to note that we provide a FIPS compliant version of SFTPPlus using the OpenSSL FIPS object Module by Open Source Software Institute which is FIPS 140-2 validated and certified by NIST - Certificate No. 733. The certificate states: "......Products which use the above identified cryptographic module may be labeled as complying with the requirements of FIPS 140-2 .....".

The Security Policy for the OpenSSL FIPS Object module is available here by pdf download. (1,363kb 45 pages).

               

Selected Customers & Users

 

Latest News:

Dec 07: Release v1.5 now available

Mar 07: HP-UX supported on Itanium

Jan 07: PGP supported

Jun 06: os/390 & Solaris x86 supported

Mar 06: FIPS 140-2 compliant version available.

Nov 05: Server Edition is now available.

Sep 05:
FTPS and HTTPS supported

______________________________

Trials
Software available for supported trial on request.

___________________________

Requirements & supported platforms
Standard SSH SFTP

- Windows NT/XP/2000/2003

- UNIX (
HP-UX (Intel & Itanium), AIX, Solaris Sparc, Solaris x86, Tru64)
- Linux (Red Hat, SUSE etc) - Intel, PPC, SPARC, Alpha
- Mainframe (os/390, z/OS)

___________________________

Roadmap includes:

- FIPS 140-2 accreditation

- Support for:

  • AS/400

  • Mac

  • OpenVMS

  • Tandem/NonStop

  • and other platforms

Check for availability

___________________________

Click for Pricing information
 

___________________________

Enquiries: sales@proatria.com or use our Sales Enquiry form. Our sales and pre-sales technical teams will promptly respond.  

___________________________

Download Overview for SFTPPlus (pdf)

Download Features for SFTPPlus (pdf)

Download FAQ for SFTPPlus (pdf)

Download Introduction to Pro:Atria (pdf)

 

   

 

 
Typical Scenarios - our assessment - more details on request  
1=most suitable    2=good   3=average   blank=n/a    
High volume of transfers - depends on scenario 2
Large files (eg 10gb+) 2
Tight control of access to files  
Large numbers of 3rd parties 2
Internal server to server 2
Support for standard protocols 1
ease of use 2
Administration 2
Minimal 3rd party software requirements 1
Minimal server requirements 1
Ease of firewall configuration 1
Ease of licensing 1
Scalability 2
Integration (client) 1
Integration (server) 1
Customisation 1
Cost 1
Reports          
 
The messages are held in a standard database and can therefore be queried using sql.  This means that customised reporting is very easy.  SFTPPlus can also produce reports using web pages and, as these are written with a scripting language (php), they can be fully customised.

The information available includes:
- User name
- server name
- client ip address
- name of file transferred
- transfer direction
- size
- start time & end time
- user logging on and off

Queries would be able to produce summaries including: by user, bytes in a month, bytes per hour etc.  We are able to provide pre-defined queries on request.
 
   
 
Authentication          
           
The userid & password storage can be configured depending on requirements.  The SSH protocol (used by SFTPPlus) ensures all traffic is encrypted, so passwords are never transmitted in clear text.   

The client can use passwords or public/private key for authentication.  If passwords are used and automation is required, then these can either be stored in  the local configuration file, or made available via a database.  SFTPPlus stores a one way hash of the password in the database (not the password itself).   

If using passwords, the server verifies the password either in the database by comparing the one way hash,  or using the native OS system (eg Active Directory for Windows).    

If using public/private key the server verifies the client has used the correct public key, and no password is required.    
 

SFTPPlus is provided as a fully supported server and/or client for enterprises who wish to use the security of SSH with open standards together with additional audit and automation for enterprise file transfers. Transfers may be made to/from internal as well as third party external SFTP servers with NO requirement for additional software at the server side. SFTPPlus for servers enables both sides to have the same audit and control - if preferred.

SFTPPlus can easily be adapted and standard facilities include:

  • Automatic transfer to single or multiple destinations of any file.

  • Monitor an 'inbox' directory for a file, or wait for a triggering event.

  • Take a copy of the file and generate a checksum.

  • All actions audited

  • Alerts raised for specified conditions – including email

  • Option to retrieve a response file after a successful upload

  • Option to add date and timestamp to avoid duplicate names

  • Pre and post processing available for transfers

  • SFTPPlus client runs as a service in Windows (Unix/Linux as a daemon)

  • All files archived with a date & time stamp

  • Support for FTP and FTPS (FTP over SSL)

  • Support for HTTP and HTTPS

  • Server & client editions

  • Database for authentication

  • Centralised administration

  • Server and Client

    The client component is used to send files to the server, or pull files from the server.


    With
     the SFTPPlus server installed at your site, and the client (SFTPPlus or other) installed at a customer site, then the customer can send files to you, and get files from you.
     
    With the SFTPPlus client installed at your site, and the server (SFTPPlus or other) installed at a third party site, then you can send files to the third party and pull files from them as well.
     
    Therefore the customers and third parties can use a standard sftp client or server as appropriate but if they also use SFTPPlus they can have better control, automation and audit.  They can also have a pre-configured install to work with your system.
     
    Therefore in some scenarios you may require the server only or client only or both.

    Features - Server

    Ø All actions audited
    Ø Alerts raised for specified conditions – including email
    Ø Option to retrieve a response file after a successful upload
    Ø Date and timestamp added to avoid duplicate names
    Ø Pre and post processing available for transfers
    Ø All files archived with a date & time stamp
    Ø Centralised Administration
    Ø Database for authentication

    Features - Client

    Ø Automatic transfer to single or multiple destinations of any file.
    Ø Monitor an 'inbox' directory for a file, or wait for a triggering event.
    Ø Take a copy of the file and generate a checksum.
    Ø All actions audited
    Ø Alerts raised for specified conditions – including email
    Ø Checkpoint restart
    Ø Option to retrieve a response file after a successful upload
    Ø Date and timestamp added to avoid duplicate names
    Ø Pre and post processing available for transfers
    Ø SFTPPlus runs as a service in windows daemon in Unix
    Ø All files archived with a date & time stamp
    Ø Automated restart

    Pricing:
    SFTPPlus is priced to suit every environment and includes options for:

  • Server edition

  • Client edition

  • Single or multi-platform usage

  • In all cases:

  • Unlimited usage (including concurrent users & connections, unlimited files sizes & numbers etc.) 

  • All functionality included

  • Upgrades free as part of support package

  • Per server (per installation)

  • or

  • Unlimited installations on a platform on one site

  • Unlimited enterprise usage across the enterprise countrywide (Single or multi-platform usage)

  • Unlimited enterprise usage across the enterprise worldwide (Single or multi-platform usage)

  • Pricing for your customers and third parties to use SFTPPlus as well. They can use a standard sftp client or server as appropriate but if they also use SFTPPlus they can have better control, automation and audit.  They can also have a pre-configured install to work with your system.

    • Public sector and educational discounts

    • Consultancy available for additional customisation and configuration.

    Enquiries: sales@proatria.com or use our Sales Enquiry form. Our sales and pre-sales technical teams will promptly respond.  

    www.sftpplus.com

    See Overview for SFTPPlus

    See Uses for SFTPPlus

    See FAQ for SFTPPlus

    Download Overview for SFTPPlus (pdf)

    Download FAQ for SFTPPlus (pdf)

    Download Features for SFTPPlus (pdf)

    Download Introduction to Pro:Atria (pdf)

    This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (http://www.openssl.org/)

    Windows XP (WindowsXP, WinXP, Win XP, WXP) windows NT (WindowsNT, WinNT, Win NT, WNT), Windows 2003 (Win 2003, Win2003, W2003), Windows .Net Server (Win .Net Server, Win.Net Server), Windows Server 2003 (Win Server 2003, WinServer 2003) Windows 2000 (Windows2000, W2K, Win 2K, Win2K, Win2000, Win 2000, W2000) Windows 98 (Windows98, Win98, Win 98), Vista

    Mainframe, IBM OS/390 (os390, MVS, zSeries, z/OS, zos, z series, V2R10, V1R1, V1R2, V1R3, V1R4), VM, VSE, Linux, IBM OS/400 (os400, A/S 400, as400, iSeries, i series, AS/400, i5/OS V5R3, i5os) UNIX, IBM AIX (pSeries, p series), HP-UX (HPUX, HP UNIX), Sun Solaris, Compaq Tru64 (Tru 64), Novell Netware (Bindery, NDS), Linux, DEC VAX/VMS, Open VMS, OpenVMS, Oracle, SAP, MQ,

    SSH server, SSH client, SFTP server, SFTP client, FTPS server, FTPS client, HTTPS, HTTP, FTP/S, solaris sparc solaris x86, mac osx, mac os x, mac 10, mac 9, Tandem, non stop, NonStop, HPUX Itanium HP-UX, PGP

    TCP/IP (TCPIP), ODBC, FTP, Lotus Notes, Lotus Domino, Websphere, Apache Tomcat, BEA Web Logic (WebLogic), Tivoli Netview, Sun ONE Application Server, Microsoft .NET, SQL, LDAP, SQL Server, RACF (SecureWay Security Server), CA-ACF2, CA-Top Secret, Internet Explorer 6.x (IE6, IE 6), Internet Explorer 5.x (IE5, IE 5), Netscape 7.x, Netscape 6.x, Firefox, Mozilla, Opera

    Completing the jigsaw
    with solutions from:

     
    Identity Management, IdM, IAM, Provisioning, enhanced, managed, Secure File Transfer, Network, website, availability, performance, monitoring, monitor, Password Management, enterprise software solutions. CyberFusion, SIFT, SecurPass, Pro:Atria, EUA, RBAC, web site, single signon, sso, password synchronisation, password, self reset, Windows XP (WindowsXP, WinXP, Win XP, WXP) windows NT (WindowsNT, WinNT, Win NT, WNT), Windows 2003 (Win 2003, Win2003, W2003), Windows .Net Server (Win .Net Server, Win.Net Server), Windows Server 2003 (Win Server 2003, WinServer 2003) Windows 2000 (Windows2000, W2K, Win 2K, Win2K, Win2000, Win 2000, W2000) Windows 98 (Windows98, Win98, Win 98) Mainframe, IBM OS/390 (os390, MVS, zSeries, z/OS, zos, z series, V2R10, V1R1, V1R2, V1R3, V1R4), VM, VSE, Linux, IBM OS/400 (os400, A/S 400, as400, iSeries, i series, AS/400, i5/OS V5R3, i5os) UNIX, IBM AIX (pSeries, p series, rs6000, rs/6000), HP-UX (HPUX, HP UNIX), Sun Solaris, Compaq Tru64 (Tru 64), Novell Netware (Bindery, NDS), Linux, DEC VAX/VMS (OpenVMS, Open VMS), Oracle, SAP, MQ, TCP/IP (TCPIP), ODBC, FTP, Lotus Notes, Lotus Domino, Websphere, Apache Tomcat, BEA Web Logic (WebLogic), Tivoli Netview, Sun ONE Application Server, Microsoft .NET, SQL, LDAP, SQL Server, RACF (SecureWay Security Server), CA-ACF2, CA-Top Secret, Internet Explorer 6.x (IE6, IE 6), Internet Explorer 5.x (IE5, IE 5), Netscape 7.x, Netscape 6.x, Firefox, Mozilla, Opera , proatria, uk, Pro:Atria, proatria, uk, yeovil, somerset, west country, england, united kingdom, uk, great britain, gb,website design, webs by design, webs-by-design.co.uk, webs by design (global) ltd, bob osborn