SAP Knowledge Base Article - Public

2653173 - Generating SSH Key pair and uploading on SuccessFactors SFTP servers

Symptom

  • There is a requirement to connect to the SAP SuccessFactors hosted SFTP server without using a password.
  • There is a requirement to configure SSH key authentication for a SAP SuccessFactors hosted SFTP server.
  • How to create an automatic feed into SAP SuccessFactors SFTP Server without using a password?
  • How to connect to a SAP SuccessFactors hosted SFTP server using an SSH key?

Environment

  • SAP SuccessFactors HCM Suite
  • SAP SuccessFactors Learning

Resolution

SSH key authentication allows connecting to the SAP SuccessFactors SFTP server without providing a password.

To use this authentication method, an SSH key pair must be generated. The key pair consists of:

  • Private key: Remains with you and must never be shared.
  • Public key: Must be provided for installation on the SAP SuccessFactors SFTP server.

Generating SSH Key:

To generate the SSH public and private key pairs, please refer to KBA 2518009 - Configuring SFTP for SAP HCI: Generating Key Pairs

Another option is to follow the below URL: https://www.ssh.com/ssh/keygen

Please generate the SSH key using SSH-RSA (2048-bit or 4096-bit) or ECDSA. Note: Ed25519 is currently not supported for SAP SuccessFactors SFTP. 

Important: Although the references above provide guidance on how to generate the SSH key pair, this process must be performed entirely by the customer. SAP Technical Support cannot assist with generating the public and private key pair. SAP Technical Support is only responsible for importing the public key into the SAP SuccessFactors SFTP server.
If assistance is required while generating the key pair, contact the support team responsible for the tool being used to generate the keys or your internal IT team for further assistance.

Uploading SSH Key:

Please submit a case under the component LOD-SF-PLT-FTPS for the technical team to proceed with the SSH key upload in the SF SFTP account.

In the case you need to provide:

  • Company ID
  • SFTP Account Name (username)
  • Data center 
  • SSH Key (attached)


General notes:

  • The Public Key must be provided in .pub or .txt format otherwise we are unable to install it.
  • Make sure to specify the SFTP username that you want the public key installed on, along with the data center.
  • iContent SFTP accounts are eligible.
  • If you are requesting for both test and production instances, please provide both SFTP usernames and specify which public key you want installed on each one.
  • SFTP usernames must be created and provided to Customer Support before you request SSH access.
  • It is possible to have multiple SSH keys for one SFTP account. This way, you can have different login options for one account.
  • Both public-key and password authentication can be used on the same server. If public-key authentication fails, it will go to password authentication.

**NOTES for support, please see "Internal memo" section of this KBA for your reference.

See Also

  • KBA 2518009 - Configuring SFTP for SAP HCI: Generating Key Pairs
  • KBA 2187183 - SFTP Account Standards for SAP SuccessFactors

Keywords

SSH public and private key pair, upload SSH Key, import, install keys on SFTP, public key, SFTP Passwords, SFTP keys, Password less, Password less, Key Exchange, SFTP Accounts, FTP, SFTP credentials, RSA, SFTP Certificates, SFTP Connection, SFTP failed connection, token , KBA , LOD-SF-PLT-FTPS , SFTP Account Creation, Reset Password & Install SSH Service , How To

Product

SAP SuccessFactors HCM Suite all versions ; SAP SuccessFactors Learning all versions