Thank you for the swift answer. I suppose we don’t necessarily need to make use of FTPS. However, I do have some questions on best practices for managing server private keys on the SFTP server. Our situation is as follows:
We would like to expose a SFTP file server to our external customers (about 5000 different clients), and to keep it simple, the clients will be authenticating to the SFTP server using username/password authentication, as this is what the clients are used to today. We might change to an SSH-key authentication in the future, but for now we will make use of username/password.
We still need to have a private key associated with the SFTP server itself such that the clients can establish a SSH connection (as per your documentation,
https://www.rebex.net/sftp.net/features/private-keys.aspx).
What are the best practices for managing and rotating the SFTP server private key(s)? And would you suggest using multiple private keys that are rotated? And if so, how do we go about implementing it?