Introduction
When we need to access an OIC SFTP endpoint from WinSCP using SSH key-based authentication, we need to generate an SSH key pair.
The key pair consists of:
Private Key – stored securely on the client/WinSCP machine.
Public Key – provided/configured on the SFTP side for the respective user.
WinSCP – uses the private key during SFTP authentication.
OIC SFTP – uses the corresponding public key to authenticate the client.
There are two commonly used approaches to generate the SSH key pair:
- Windows Command Prompt using ssh-keygen
- PuTTYgen
1. Architecture / High-Level Flow
Flow
KEY GENERATION
|
+----------+----------+
| |
ssh-keygen PuTTYgen
Command Prompt Windows GUI
| |
+----------+----------+
|
SSH Key Pair
+--------+--------+
| |
Private Key Public Key
| |
| +----> Configure on
| SFTP/OIC side
|
+----> Configure in WinSCP
|
|
SFTP over SSH
|
v
OIC SFTP Endpoint
Important: The private key must be kept secure and should never be shared with the SFTP server or other unauthorized users.
Option 1 – Generate SSH Key Using ssh-keygen
Windows provides the OpenSSH ssh-keygen utility, which can be used from Command Prompt.
Step 1: Open Command Prompt
Open Command Prompt and execute:
ssh-keygen -t rsa -b 2048 -m pem
What does the command mean?
ssh-keygen
|
+-- -t rsa → RSA key type
|
+-- -b 2048 → 2048-bit key
|
+-- -m pem → PEM output format
Step 2: Specify the Key File Name
The command will prompt:
Enter file in which to save the key
(C:\Users\<username>/.ssh/id_rsa):
Provide the required location and filename.
For example:
C:\Users\<username>\OneDrive - abc\John\TRN_John_OICSFTP_Key
If the file already exists, you may see:
... already exists.
Overwrite (y/n)?
Enter: y
only if you intentionally want to replace the existing key.
3. Enter the Passphrase
Next, the command prompts:
Enter passphrase (empty for no passphrase):
and: Enter same passphrase again:
You can configure a passphrase for additional protection.
However, before using the key with an automated integration/client, verify whether the target OIC SFTP/WinSCP configuration supports the selected private-key/passphrase setup.
4. Generated Files
After successful execution, two files are generated.
For example:
TRN_John_OICSFTP_Key
TRN_John_OICSFTP_Key.pub
Private Key
TRN_John_OICSFTP_Key
This is the private key.
It should be stored securely.
Public Key
TRN_John_OICSFTP_Key.pub
This is the public key that can be provided to the SFTP server/OIC-side user configuration.
Option 2 – Generate Key Using PuTTYgen
Another option is to use PuTTY Key Generator (PuTTYgen).
This is particularly useful when the Windows environment already uses PuTTY/WinSCP.
Step 1: Open PuTTYgen
Launch:
PuTTY Key Generator
Step 2: Select RSA
Under the key type, select:
RSA
Set the key size to:
2048 bits
Step 3: Generate
Click:
Generate
Move the mouse around the blank area until the key is generated.
Step4: Save the Private Key
Click:
Save private key
Save the file securely.
For example:
TRN_John_OICSFTP_Key.ppk
The .ppk file is the PuTTY/WinSCP private-key format.
Step5: Obtain the Public Key
PuTTYgen displays the public key in the section:
Public key for pasting into OpenSSH authorized_keys file
Copy the complete public-key text.
This public key is then configured/provided on the SFTP side according to the server/OIC SFTP configuration.
Step6: Using the Key in WinSCP
Once the key pair is generated, configure WinSCP.
WinSCP Configuration
Go to:
WinSCP
↓
New Site
↓
File Protocol: SFTP
↓
Host Name
↓
Port: 22
↓
User Name
Then go to:
Advanced
↓
SSH
↓
Authentication
Select the corresponding private key.
For PuTTYgen-generated keys, this will normally be the:
.ppk
file.
For OpenSSH keys, use the appropriate private-key format supported by your WinSCP version.
Step7: Authentication Flow
During the connection, WinSCP uses the private key for authentication.
Conceptually:
WinSCP
|
| Private Key
|
v
SSH Authentication
|
v
OIC SFTP Endpoint
|
| Validates against
| Public Key
v
Authentication
Successful
|
v
SFTP Session
Conclusion
For OIC SFTP access through WinSCP, we can generate the SSH key pair either through Windows ssh-keygen or PuTTYgen.
Recommended practice: Keep the private key protected and share only the public key with the SFTP/OIC administrator.
No comments:
Post a Comment