SAP Knowledge Base Article - Public

3711560 - SSH RSA algorithm for SF SFTP public key authentication is disabled in few countries.

Symptom

  • SFTP integration for SuccessFactors Employee Central cannot be established in DC66 while SSH-RSA is the only supported algorithm for SF SFTP public key authentication. 
  • SSH-RSA is prohibited by local (Queensland Government / ASD) security policy, as it is no longer considered secure.

  • ASD-approved cryptographic standards do not permit SSH-RSA, as a result, customer's in DC66 cannot enable SSH-RSA on their SecureTransport system due to regulatory compliance restrictions.

Environment

SAP SuccessFactors HCM Suite

Reproducing the Issue

  1. Attempt to connect to the server in DC66 using SSH-RSA encryption.
  2. Observe that the connection succeeds when SSH-RSA is used.
  3. Remove SSH-RSA and attempt to connect using alternative algorithms such as rsa-sha2-512 or ECDSA.
  4. Observe that the connection fails as these algorithms are not supported by the current server configuration.

Cause

This is an expected behavior as SHA-256/SHA-512 keys are not supported in the current version of the SFTP server software.

Resolution

The latest version of the SFTP software is planned to be deployed on 1H 2026 release (b2605)

For release timelines, please review SAP SuccessFactors Product Release & Road Map Information.

See Also

Keywords

KI2H2025, SSH-RSA, SHA-512, SHA-256, ECDSA, Security, SFTP, Connection, unsupported algorithm, Compliance, SF Integration Centre, Security Center.
, KBA , LOD-SF-PLT-FTPS , SFTP Account Creation, Reset Password & Install SSH Service , Product Enhancement

Product

SAP SuccessFactors HCM Suite 2511