Supported FTPS algorithms

Buru SFTP Server supports the following TLS/SSL algorithms for FTPS connections. Unlike SSH algorithms, the selection of FTPS algorithms is not configurable. For FTP/FTPS endpoint configuration, see Enable FTP/FTPS.

TLS protocol versions

  • TLS 1.2
  • TLS 1.1 (deprecated)
  • TLS 1.0 (deprecated)

TLS cipher suites

RSA certificate, RSA key exchangeEncryptionMAC
RSA_WITH_AES_128_GCM_SHA256AES/GCMAEAD
RSA_WITH_AES_256_GCM_SHA384AES/GCMAEAD
RSA_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
RSA_WITH_AES_256_CBC_SHA256AES/CBCSHA-256
RSA_WITH_AES_128_CBC_SHAAES/CBCSHA-1
RSA_WITH_AES_256_CBC_SHAAES/CBCSHA-1
RSA_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
RSA_WITH_DES_CBC_SHADES/CBCSHA-1
RSA_WITH_RC4_128_MD5RC4MD5
RSA_WITH_RC4_128_SHARC4SHA-1
RSA_EXPORT_WITH_RC4_40_MD5RC4MD5
RSA_EXPORT_WITH_RC2_CBC_40_MD5RC2/CBCMD5
RSA_EXPORT_WITH_DES40_CBC_SHADES/CBCSHA-1
RSA_EXPORT1024_WITH_DES_CBC_SHADES/CBCSHA-1
RSA_EXPORT1024_WITH_RC4_56_SHARC4SHA-1
RSA certificate, ECDHE key exchangeEncryptionMAC
ECDHE_RSA_WITH_AES_128_GCM_SHA256AES/GCMAEAD
ECDHE_RSA_WITH_AES_256_GCM_SHA384AES/GCMAEAD
ECDHE_RSA_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
ECDHE_RSA_WITH_AES_256_CBC_SHA384AES/CBCSHA-384
ECDHE_RSA_WITH_AES_128_CBC_SHAAES/CBCSHA-1
ECDHE_RSA_WITH_AES_256_CBC_SHAAES/CBCSHA-1
ECDHE_RSA_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
ECDHE_RSA_WITH_RC4_128_SHARC4SHA-1
ECDSA certificate, ECDHE key exchangeEncryptionMAC
ECDHE_ECDSA_WITH_AES_128_GCM_SHA256AES/GCMAEAD
ECDHE_ECDSA_WITH_AES_256_GCM_SHA384AES/GCMAEAD
ECDHE_ECDSA_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
ECDHE_ECDSA_WITH_AES_256_CBC_SHA384AES/CBCSHA-384
ECDHE_ECDSA_WITH_AES_128_CBC_SHAAES/CBCSHA-1
ECDHE_ECDSA_WITH_AES_256_CBC_SHAAES/CBCSHA-1
ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
ECDHE_ECDSA_WITH_RC4_128_SHARC4SHA-1
RSA certificate, DHE key exchangeEncryptionMAC
DHE_RSA_WITH_AES_128_GCM_SHA256AES/GCMAEAD
DHE_RSA_WITH_AES_256_GCM_SHA384AES/GCMAEAD
DHE_RSA_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
DHE_RSA_WITH_AES_256_CBC_SHA256AES/CBCSHA-256
DHE_RSA_WITH_AES_128_CBC_SHAAES/CBCSHA-1
DHE_RSA_WITH_AES_256_CBC_SHAAES/CBCSHA-1
DHE_RSA_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
DHE_RSA_WITH_DES_CBC_SHADES/CBCSHA-1
DHE_RSA_EXPORT_WITH_DES40_CBC_SHADES/CBCSHA-1
DSS certificate, DHE key exchangeEncryptionMAC
DHE_DSS_WITH_AES_128_GCM_SHA256AES/GCMAEAD
DHE_DSS_WITH_AES_256_GCM_SHA384AES/GCMAEAD
DHE_DSS_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
DHE_DSS_WITH_AES_256_CBC_SHA256AES/CBCSHA-256
DHE_DSS_WITH_AES_128_CBC_SHAAES/CBCSHA-1
DHE_DSS_WITH_AES_256_CBC_SHAAES/CBCSHA-1
DHE_DSS_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
DHE_DSS_WITH_DES_CBC_SHADES/CBCSHA-1
DHE_DSS_WITH_RC4_128_SHARC4SHA-1
DHE_DSS_EXPORT_WITH_DES40_CBC_SHADES/CBCSHA-1
DHE_DSS_EXPORT1024_WITH_DES_CBC_SHADES/CBCSHA-1
DHE_DSS_EXPORT1024_WITH_RC4_56_SHARC4SHA-1
Anonymous, DHE key exchange (no certificate)EncryptionMAC
DH_anon_WITH_AES_256_CBC_SHA256AES/CBCSHA-256
DH_anon_WITH_AES_128_CBC_SHA256AES/CBCSHA-256
DH_anon_WITH_AES_256_CBC_SHAAES/CBCSHA-1
DH_anon_WITH_AES_128_CBC_SHAAES/CBCSHA-1
DH_anon_WITH_3DES_EDE_CBC_SHA3DES/CBCSHA-1
DH_anon_WITH_DES_CBC_SHADES/CBCSHA-1
DH_anon_WITH_RC4_128_MD5RC4MD5

TLS extensions

Buru supports the Server Name Indication (SNI) extension and the Renegotiation Indication extension.

Elliptic curves

Elliptic curves used by ECDHE cipher suites:

Curve IDCurve Name
NistP256NIST P-256
NistP384NIST P-384
NistP521NIST P-521
BrainpoolP256R1Brainpool P-256 R1
BrainpoolP384R1Brainpool P-384 R1
BrainpoolP512R1Brainpool P-512 R1
Curve25519X25519

On this page