This is how you set up an FTP server as a target for your backups: from the form via encryption and the certificate to the saved target.
What you need
- the credentials: server, user name and password,
- a folder on the server that nobody without authorisation can reach,
- in case the certificate of the server does not pass the check: the fingerprint of the certificate as your provider states it.
FTPS is not SFTP
FTPS is FTP with encryption. SFTP is file transfer over SSH, a protocol of its own on a port of its own. There is a separate target type for it: Store backups on an SFTP server.
Step 1: Choose the target type
Open the Targets page and click Add target. Choose FTP / FTPS.
- The target types that exist. FTP / FTPS is the second.
- Dismiss closes the selection.
The plugin speaks FTP through the PHP extension cURL. If cURL is missing, it takes the FTP extension of PHP. If both are missing, FTP / FTPS is greyed out, and the reason is below the selection.
Step 2: Fill in the form
- Name is your name for the target. The plugin suggests “FTP / FTPS 1”; any name that is not yet taken works.
- Server is the host name or the IP address, without ftp://.
- User name is required. The plugin does not offer anonymous FTP.
- Password is required.
- Folder on the FTP server may stay empty: then the folder in which you land after logging in applies. A path without a slash at the start counts from there. The plugin creates missing folders.
- Save saves the target and tests the connection immediately.
- Test connection checks the entered values without saving.
- Cancel closes the form.
You do not need more in the Compact view. For everything else the defaults apply: FTPS with TLS, passive mode and port 21.
The folder must not be publicly reachable
Make sure that nobody without authorisation can access the folder, for example via a web address if the FTP account lies in a web space. The plugin puts protection files into its folders. It does not check the folder from outside: it never sends test requests to other people’s servers.
Step 3: Set encryption and transfer mode
This step is only necessary if the defaults do not suit your server. For this, switch to the Extended view. The form then shows further fields.
- Encryption sets whether and how the connection is encrypted.
- Transfer mode offers Passive (recommended) and Active.
- Port may stay empty: then 21 applies, for implicit FTPS 990.
- Connection timeout (seconds) takes 3 to 60, the default is 10.
- Accepted key of the FTP server is empty as long as you have not accepted a certificate. Accept this certificate fills the field (step 5).
Encryption
| Choice | Meaning |
|---|---|
| FTPS with TLS (recommended) | The default. The connection is encrypted, and the plugin checks the certificate of the FTP server. |
| None: password and data can be read on the way | FTP without encryption. The form warns below the field as long as this is chosen. |
| FTPS, implicit (port 990, outdated) | The outdated form of FTPS and the last choice. |
There is no silent fallback: if the server does not offer TLS, the connection test fails and says so. If you want to accept the risk, you choose None: password and data can be read on the way yourself.
- Encryption is set here to the choice without encryption.
- The warning is below the field as long as this choice applies.
The warning reads: Without encryption the password and all data travel in clear text. Anyone on the way can read them. The result of a successful connection test also names the risk.
Passive or active
The default is passive mode. About active mode the form says: Active mode only works when the FTP server can open a connection to this web server on its own. Most hosting providers do not allow that.
Step 4: Test the connection
Click Test connection. The plugin logs in to the server and tries everything it needs for backups: it writes a small file in two sections, asks for its size, renames it, reads it back, lists the folder and deletes the file.
If the test succeeds, the result appears in green above the buttons. Below the result are warnings and notes, if there are any. The picture shows a test with both.
- The result of the test appears in green: Connection works: a test file was written, read back and deleted.
- The warning appears there if you have accepted a certificate (step 5): The certificate is not checked against the list of trusted authorities; the plugin trusts the key you accepted.
- The note appears there if the server refused a protection file.
If the server refuses a protection file, this is stated below the result, in the picture at 3. Some servers forbid files whose name begins with a dot. The plugin stores the backups anyway.
Step 5: Check the certificate if the test rejects it
With FTPS, the plugin checks the certificate of the FTP server against the list of trusted authorities that WordPress brings along, and against the name of the server. If the certificate passes the check, you skip this step. If it does not pass, the test fails and shows the certificate.
- The reason why the certificate was rejected.
- The details of the certificate: for whom it is issued, by whom, until when it is valid, and its fingerprint (SHA-256).
- Accept this certificate takes the key of the certificate over into the form and tests once more.
The plugin names the reason, for example:
- The certificate is not issued for this server name.
- The certificate is self-signed: no trusted authority has confirmed it.
- The certificate comes from an authority that is not in the list of trusted authorities.
- The certificate has expired.
Above the button it says what accepting means. Compare the fingerprint with the one your provider states. Accept the certificate only if both are the same. From then on the plugin trusts exactly this key and no longer checks who issued the certificate. The check is not switched off by this: if the server shows a different key, the test fails. The accepted key is only stored with Save.
If the test succeeds after accepting, the warning about the accepted key appears below the result. The picture in step 4 shows it.
If the server shows a different key later
Then the target no longer passes its test. Test connection in the form of the target names the reason: The server shows a different key than the one you accepted. It may have a new certificate, or someone may be in between. Accept the new certificate only if you know the reason. If in doubt, ask your provider for the new fingerprint.
Step 6: Save
Click Save. The plugin saves the target, tests the connection once more and reports the result. A target is usable only after a successful test.
- All targets are connected.
- The message names the target: saved and connected.
- The new target is in the list. The green dot means: connected. In front of the name is the icon of a server.
Your first target brings the plan “Daily backup” with it: daily at a random time, everything, this target, Max. backups 7. The plan is paused until you switch it on. You choose another target on the Backup page in the tile Backup plans in a plan. The free version allows two plans and one target per plan.
If the test fails
- The cause in plain language.
- Show log opens the general log. The details of the test are there.
- The original error messages: Message from the target is the last answer of the FTP server, Message from cURL the message of the transfer. Neither is translated; credentials, folders and server names are masked in them.
| Message | What you can do |
|---|---|
| The target cannot be reached. Check the server name and the port; the host of this website may block the port. | Check Server and, in the Extended view, Port. Ask the hosting provider of your website whether it allows outgoing connections on this port. |
| The target refused the login. Check user name and password. | Enter the credentials again. |
| The server does not offer encryption (TLS). Choose “None” under Encryption only if you accept the risk. | Ask your provider for FTPS. Without encryption, password and backups can be read on the way. |
| The certificate of the target did not pass the check. | See step 5. |
| The data connection could not be established. Try the other transfer mode; the host of this website may block the ports. | In the Extended view, change the Transfer mode and test once more. |
| The target does not allow everything the plugin needs. | Below it is what is missing, for example renaming a file. Give the FTP user this permission, or ask your provider. Without it, the target is not usable. |
| The target reports that there is no space left. | Free up space on the server, or choose a different target. |
| Sending the data failed. Possible causes: the connection was interrupted, or there is no space left at the target. | This line additionally appears below the cause if sending broke off in the middle of the transfer. Check the free space on the server and test once more. |
| This value is not valid. | The message appears in red at the field. For Server: enter only the host name or the IP address, without ftp:// and without a path. |
Good to know
- The backups are stored on the server under
<folder>/cloneworx-backup-<code>/<backup>/. You do not have to create the folder of the plugin. - An upload first goes into a file with the extension
.partand only gets its name at the end. After that, the plugin compares the size on the server with the local size. FTP does not know checksums. - Backups that are stored only at an FTP target you do not download through the plugin, but with your FTP program. Restore, check and finding backups read directly from the server.
- FTP does not name the free space. In the Extended view, the tile Targets and space shows a dash there.
- The plugin stores the password encrypted. When editing, the field only shows stored, leave empty to keep.
- Without cURL: The FTP extension encrypts, but does not check the certificate of the server. Implicit FTPS and accepting a certificate are then not available. The form says so, and the connection test warns.
- Web server without TLS for FTP: If your web server cannot encrypt FTP, the field Encryption offers only the choice without encryption. The result of the connection test then names the risk.
See also
- Which target suits you?
- The “Targets” page
- Renew the credentials of a target
- Check backups at a target and clean up leftovers
- Schedule backups automatically
On the command line
WP-CLI not set up yet? How to install WP-CLI.
The command line does not accept the password; so you set up an FTP target on the Targets page. Everything else also works with WP-CLI:
# Show targets with ID and state wp cloneworx-backup target list # Test the connection wp cloneworx-backup target test ftp-1 # Change the transfer mode, then test again wp cloneworx-backup target edit ftp-1 --set-mode=active wp cloneworx-backup target test ftp-1 # Create a backup plan that backs up to this target wp cloneworx-backup plan add --targets=ftp-1 --rhythm=daily --time=03:15 --name="Nachts" # Check the backups at this target wp cloneworx-backup target check ftp-1