Monday, September 28, 2026

OIC SFTP: Generate SSH Private/Public Key Pair for WinSCP Access

Introduction

When we need to access an OIC SFTP endpoint from WinSCP using SSH key-based authentication, we need to generate an SSH key pair.

The key pair consists of:

Private Key – stored securely on the client/WinSCP machine.

Public Key – provided/configured on the SFTP side for the respective user.

WinSCP – uses the private key during SFTP authentication.

OIC SFTP – uses the corresponding public key to authenticate the client.

There are two commonly used approaches to generate the SSH key pair:

  1. Windows Command Prompt using ssh-keygen
  2. PuTTYgen

1. Architecture / High-Level Flow

Flow

             KEY GENERATION

                   |

        +----------+----------+

        |                     |

   ssh-keygen              PuTTYgen

   Command Prompt          Windows GUI

        |                     |

        +----------+----------+

                   |

             SSH Key Pair

          +--------+--------+

          |                 |

     Private Key        Public Key

          |                 |

          |                 +----> Configure on

          |                       SFTP/OIC side

          |

          +----> Configure in WinSCP

                         |

                         |

                  SFTP over SSH

                         |

                         v

                  OIC SFTP Endpoint

Important: The private key must be kept secure and should never be shared with the SFTP server or other unauthorized users.

Option 1 – Generate SSH Key Using ssh-keygen

Windows provides the OpenSSH ssh-keygen utility, which can be used from Command Prompt.

Step 1: Open Command Prompt

Open Command Prompt and execute:

ssh-keygen -t rsa -b 2048 -m pem

What does the command mean?

ssh-keygen

   |

   +-- -t rsa       → RSA key type

   |

   +-- -b 2048      → 2048-bit key

   |

   +-- -m pem       → PEM output format

Step 2: Specify the Key File Name

The command will prompt:

Enter file in which to save the key

(C:\Users\<username>/.ssh/id_rsa):

Provide the required location and filename.

For example:

C:\Users\<username>\OneDrive - abc\John\TRN_John_OICSFTP_Key

If the file already exists, you may see:

... already exists.

Overwrite (y/n)?

Enter: y

only if you intentionally want to replace the existing key.

3. Enter the Passphrase

Next, the command prompts:

Enter passphrase (empty for no passphrase):

and: Enter same passphrase again:

You can configure a passphrase for additional protection.

However, before using the key with an automated integration/client, verify whether the target OIC SFTP/WinSCP configuration supports the selected private-key/passphrase setup.

4. Generated Files

After successful execution, two files are generated.

For example:

TRN_John_OICSFTP_Key

TRN_John_OICSFTP_Key.pub

Private Key

TRN_John_OICSFTP_Key

This is the private key.

It should be stored securely.

Public Key

TRN_John_OICSFTP_Key.pub

This is the public key that can be provided to the SFTP server/OIC-side user configuration.


Option 2 – Generate Key Using PuTTYgen

Another option is to use PuTTY Key Generator (PuTTYgen).

This is particularly useful when the Windows environment already uses PuTTY/WinSCP.

Step 1: Open PuTTYgen

Launch:

PuTTY Key Generator

Step 2: Select RSA

Under the key type, select:

RSA

Set the key size to:

2048 bits

Step 3: Generate

Click:

Generate

Move the mouse around the blank area until the key is generated.

Step4: Save the Private Key

Click:

Save private key

Save the file securely.

For example:

TRN_John_OICSFTP_Key.ppk

The .ppk file is the PuTTY/WinSCP private-key format.

Step5: Obtain the Public Key

PuTTYgen displays the public key in the section:

Public key for pasting into OpenSSH authorized_keys file

Copy the complete public-key text.

This public key is then configured/provided on the SFTP side according to the server/OIC SFTP configuration.

Step6: Using the Key in WinSCP

Once the key pair is generated, configure WinSCP.

WinSCP Configuration

Go to:

WinSCP

   ↓

New Site

   ↓

File Protocol: SFTP

   ↓

Host Name

   ↓

Port: 22

   ↓

User Name

Then go to:

Advanced

   ↓

SSH

   ↓

Authentication

Select the corresponding private key.

For PuTTYgen-generated keys, this will normally be the:

.ppk

file.

For OpenSSH keys, use the appropriate private-key format supported by your WinSCP version.

Step7: Authentication Flow

During the connection, WinSCP uses the private key for authentication.

Conceptually:

                 WinSCP

                   |

                   | Private Key

                   |

                   v

             SSH Authentication

                   |

                   v

             OIC SFTP Endpoint

                   |

                   | Validates against

                   | Public Key

                   v

             Authentication

                Successful

                   |

                   v

              SFTP Session

Conclusion

For OIC SFTP access through WinSCP, we can generate the SSH key pair either through Windows ssh-keygen or PuTTYgen.

Recommended practice: Keep the private key protected and share only the public key with the SFTP/OIC administrator.

No comments:

Post a Comment

Featured Post

OIC: Extract File Name from File Path Using replace() and Regular Expression

Introduction In Oracle Integration Cloud (OIC), there are situations where an API returns a list of files along with their complete director...