This is how you set up an SFTP server as a target for your backups: from the form via the key of the server to the saved target.
What you need
- the credentials: server, user name and password or private key,
- the fingerprint of the server key as your provider states it,
- a folder on the server that nobody without authorisation can reach.
SFTP is not FTPS
SFTP is file transfer over SSH, a protocol of its own on a port of its own (22). For FTP with encryption you choose the target type FTP / FTPS: Store backups on an FTP server (FTP / FTPS).
Step 1: Choose the target type
Open the Targets page and click Add target. Choose SFTP.
- The target types that exist. SFTP carries the padlock.
- Dismiss closes the selection.
The plugin speaks SFTP through the PHP extension cURL of the web server. It brings no SSH library of its own. If cURL is missing or cannot do SFTP, SFTP is greyed out and carries the label Not available on this server. The reason is below the selection.
Step 2: Fill in the form
- Name is up to you. The plugin suggests “SFTP 1”; any name that is not yet taken works.
- Server is the host name or the IP address, without sftp://.
- User name
- Login offers Password and Private key.
- Password appears for the login with password.
- Folder on the SFTP server may stay empty: then the folder in which you land after logging in applies. A path without a slash at the start counts from there. The plugin creates missing folders.
- Test connection checks the entered values without saving.
Fields with a red star are required. In the Extended view, three fields are added. The section “The fields of the Extended view” shows them.
The folder must not be publicly reachable
Make sure that nobody without authorisation can access the folder, for example via a web address. The plugin puts protection files into its folders. It does not check the folder from outside: it never sends test requests to other people’s servers.
Step 3: Choose the login
With Password the form is complete: continue with step 4. With Private key the form swaps the field for the password for the field for the key.
- Login is set here to Private key.
- The note says how the plugin handles the key.
- Private key takes the whole text of the key file, in OpenSSH or PEM format.
- Only keys without a passphrase. The backups run on their own. A passphrase would have to be stored next to the key and would protect nothing there.
- No PuTTY format. Export the key in PuTTYgen as an OpenSSH key (menu Conversions) and paste that text.
- This is how the key is stored on the server. It is stored encrypted in the database of your website and never goes back to the browser. For every login, the plugin briefly writes it into a file on the web server and deletes it right after the login.
- A separate key for the backup. Use a key that was created exclusively for this backup and is used only for it.
A key with a passphrase, a key in PuTTY format and a public key are rejected by the form when testing and when saving. The reason then appears at the field Private key.
Step 4: Test the connection
Click Test connection. At the first test, the plugin reads the key of the server, before any login. This way your password never goes to a server that nobody has confirmed.
- Confirm the key of the server is not an error but a decision that is pending.
- The type of the key and its fingerprint, in the form in which OpenSSH shows it (SHA256:…).
- Accept this server key takes over the key and tests once more.
Step 5: Confirm the key of the server
Compare the fingerprint with the one your provider states. Click Accept this server key only if both are the same. The plugin then tests the connection once more, now with login.
- The result of the test: the connection works, a test file was written, read back and deleted.
- Save
From then on the plugin checks the key at every connection. There is no switch that turns the check off.
Step 6: Save
Click Save. Only now is the target saved with the accepted key. The plugin tests the connection once more in doing so and reports the result.
- All targets are connected.
- The message names the target: saved and connected.
- The new target is in the list. The green dot means: connected.
Step 7: Choose the target in the backup plan
- Your first target: The plugin creates the plan “Daily backup”: daily at a random time, everything, this target, Max. backups 7. The plan is paused until you switch it on.
- Another target: Choose it on the Backup page in the tile Backup plans in a plan. The free version allows two plans and one target per plan.
More on this: Schedule backups automatically.
The fields of the Extended view
- Port may stay empty: then 22 applies.
- Connection timeout (seconds) takes 3 to 60, the default is 10.
- Confirmed key of the SFTP server is set by Accept this server key. Empty means: the next connection test shows the key of the server for confirmation.
In the picture, the field for the key of the server is still empty: the first connection test is still pending.
If the test fails
| Message | What you can do |
|---|---|
| The target cannot be reached. Check the server name and the port; the host of this website may block the port. | Check Server and, in the Extended view, Port. If the hosting provider of your website blocks the port, a target that works over HTTPS, usually via port 443, remains: WebDAV, Amazon S3 or S3-compatible. |
| The target refused the login. Check user name and password. | Enter the credentials again. With a private key: check whether the public part of the key is stored for the user on the server. |
| The private key cannot be read. Only keys in OpenSSH or PEM format without a passphrase work. | Paste the whole text of the key file, with the first and the last line. |
| The key of the server could not be read. | Below the message is the reason. If the server does not answer like an SSH server, check Server and Port. |
| The key of the server is not confirmed yet. Open the target, test the connection and accept the key. | The target was saved before the key of the server was confirmed. Open the More … menu of the target, then Edit, and continue with step 4. |
| The server shows a different key than the one you confirmed. | See the next section. |
Below a message is the original error message, if there is one: Message from the target with the answer of the SFTP server and Message from cURL. Show log opens the general log with the details. More on this: The “Targets” page.
If the key of the server changes
If the server shows a different key later, the plugin connects nothing and sends nothing. The target no longer passes its test. Open the More … menu of the target, then Edit, and click Test connection: the result names both fingerprints.
- The message: the server shows a different key than the confirmed one.
- The new fingerprint and the one confirmed so far.
- Accept this server key
Accept only if you know the reason
A changed key can mean that the server was set up afresh. It can also mean that someone is sitting between your website and the server. If in doubt, ask your provider for the new fingerprint.
Good to know
- The backups are stored on the server under
<folder>/cloneworx-backup-<code>/<backup>/. You do not have to create the folder of the plugin. - The server must allow: writing, naming the size of a file, continuing an upload, renaming, reading back, listing and deleting. The connection test tries each of these and names what is missing.
- Backups that are stored only at an SFTP target you do not download through the plugin, but with your SFTP program. Restore, check and finding backups read directly from the server.
- If the server names the free space, the plugin checks before writing a backup whether it is sufficient. The tile Targets and space in the Extended view shows the free space only for local folders; for an SFTP target there is a dash.
See also
- Which target suits you?
- The “Targets” page
- Renew the credentials of a target
- Check backups at a target and clean up leftovers
On the command line
WP-CLI not set up yet? How to install WP-CLI.
The command line does not accept the password and the private key; so you set up an SFTP target on the Targets page. Everything else also works with WP-CLI:
# Show targets with ID and state wp cloneworx-backup target list # Test the connection wp cloneworx-backup target test sftp-1 # Create a backup plan that backs up to this target wp cloneworx-backup plan add --targets=sftp-1 --rhythm=daily --time=03:15 --name="Nachts" # Run the backup plan now wp cloneworx-backup plan run "Nachts" # Check the backups at this target wp cloneworx-backup target check sftp-1