Theme
Settings
System, then Settings. Seven tabs. Each one says whether its changes apply live or at the next service start.
Web server
How the Connector's own admin console is reachable.
| Setting | Notes |
|---|---|
| Bind address | address:port. 127.0.0.1:8883 is this machine only |
| TLS | None, self signed, or your own certificate and key files |
| Global rate limit | Requests per second across the whole console |
| Per IP rate limit | Requests per second per client address |
| IP allow list | Addresses or CIDRs allowed to reach the console. Empty allows all |
| Trusted proxies | Addresses whose forwarded client address is believed |
The bind address, TLS and rate limits apply at the next service start. The IP allow list applies immediately.
Choosing a TLS mode
| Mode | When |
|---|---|
| None (plain HTTP) | Only on a loopback bind. Anything reachable from the network needs TLS |
| Self signed certificate | Generated under the data directory at the next start and reused after that. Browsers warn on first contact |
| Certificate and key files | Absolute paths on this machine, PEM, readable by the service |
The admin console is never cloud reachable
There is no setting anywhere that publishes it to the internet, and SFTP.cloud never proxies to it. If you bind it to a network address, you are responsible for keeping it on a network you trust.
You can also set the bind address and TLS mode from the command line, while the service is stopped:
sh
sudo sc-conn svc stop
sudo sc-conn config web --bindto 0.0.0.0:8883 --tls selfsigned
sudo sc-conn svc startThe embedded database is single writer, so this fails with a lock error while the service is running. Stop it first.
Logging
Logging changes apply immediately. No restart.
| Setting | Notes |
|---|---|
| Level | How much is written |
| Output | Where it goes: file, stdout, stderr or syslog |
| Target | A directory for files, or a syslog address such as udp://host:514 |
| Rotation size (bytes) | |
| Files to keep | |
| Compress rotated files | |
| Rotate daily |
This is the Connector's operational log. It is not the signed operation record, which is separate, always written, and covered in Log integrity. Files to keep left at 0 keeps ten rotated files.
A new Connector writes to files in the logs directory under its data directory, rotated at 10 MB with ten kept. In a container it writes to standard output instead, which the container runtime keeps. A file output with no Target uses that same logs directory.
On Windows the service has no console, so stdout and stderr would keep nothing. Saving either one there keeps the files and tells you so.
If the destination you chose cannot be opened (a directory the service account cannot create, a syslog address that is not a udp:// or tcp:// address), the Connector falls back to the logs directory and the first line there says which destination failed and why.
Tamper evident audit log
The same tab carries the two bounds on the signed operation record. They apply immediately, and they are the only thing about that record you configure: it cannot be turned off or redirected.
| Setting | Notes |
|---|---|
| Keep for (days) | Files whose entries are all older than this are retired. Default 365, floor 7 |
| Keep at most (MB) | The audit directory is kept under this size. Default 4096, floor 256 |
The oldest files are retired first, in chain order, never from the middle, and the record stays verifiable from whatever file is the oldest kept. See How witnessed signed logging works.
Webhook
Session visibility events, delivered to an endpoint of yours.
| Setting | Notes |
|---|---|
| Deliver session events | On or off |
| Endpoint URL | Yours |
| Signing secret | Verifies deliveries came from this Connector. Required when enabled |
| Timeout (s) | |
| Retries | |
| Queue size |
Three events are delivered: a session established, refused, or revoked.
Best effort, never on the enforcement path
A webhook that is slow, down or misconfigured never delays or blocks a transfer. Deliveries are signed so your endpoint can verify they came from this Connector, and dropped rather than queued forever when your endpoint is unavailable.
Send a test delivery proves the endpoint and the signature without waiting for a real session.
SMTP
The mail server your scripts send through when they call SendMail(). Nothing else on the Connector sends email, so this tab is empty and off until you have a script that needs it.
SMTP changes apply immediately. No restart.
| Setting | Notes |
|---|---|
| Let scripts send email | Off until you fill the rest in. While off, SendMail() returns false |
| Server address and Port | Your relay. 587 with STARTTLS suits most providers |
| Encryption | STARTTLS required, STARTTLS if offered, direct TLS on 465, or none |
| Send from | The address messages come from. A script may pass its own; when it passes an empty one, this is used |
| Username and Password | Leave the username empty if your relay does not ask you to sign in |
| HELO name | Only if your provider insists on a particular name |
This is your mail server, not ours
Messages go out as you, from your address, through your relay. SFTP.cloud never sees them, never sends them for you, and cannot deliver them if your relay is down.
Choosing an encryption mode
| Mode | When |
|---|---|
| STARTTLS (required) | The usual choice, on port 587. Refuses to send if the relay will not encrypt |
| Direct TLS (port 465) | When your provider asks for it. Encrypted from the first byte |
| STARTTLS if offered | A relay you do not control that may or may not support it. Sends in the clear if it does not |
| None (plain text) | Only for a relay on this machine or on a network you fully control |
Send test message sends a real message through the saved settings, exactly the way a script would. The button stays disabled until you save, because it tests what is stored rather than what is on screen. A failure shows your relay's own words, which is usually what tells you what is wrong.
Telegram
The bot your scripts post through when they call NotifyViaTelegramBot(). Useful for alerts you want on your phone.
Telegram changes apply immediately. No restart.
| Setting | Notes |
|---|---|
| Let scripts send Telegram messages | Off until you fill the rest in |
| Bot token | From BotFather. Stored encrypted and never shown again |
| Send to | One or more chats: a numeric chat id, or a channel name starting with @ |
The bot only sends
It never reads messages and never accepts commands, so nobody can drive this Connector by messaging it. If you know Syncplify Server's Telegram integration, which does accept /status and /restart, this is deliberately not that.
To find a chat id: create the bot with BotFather, send it a message from the chat you want, then ask a chat id bot for the number. Group and supergroup ids are negative.
Send test message posts to every chat listed, and is disabled until you save.
Admin sign in
| Setting | Notes |
|---|---|
| TOTP grace (days) | How long a new administrator may sign in before two step enrollment becomes mandatory |
| Trust this device (days) | How long a remembered device skips the code. 0 disables the checkbox |
Set the trust window to 0 on any Connector reached from a machine you do not control.
Activity log
Record activity for the Activity page.
This switch controls the queryable log that feeds Activity.
The tamper evident security log is always written regardless of this switch. Turning this off saves database space; it does not reduce what is provable.
Keep activity for (days) bounds the queryable log: records older than this are removed once a day. Default 90. It bounds the searchable database only; the signed record keeps its own retention under Logging.