cancel
Showing results for 
Search instead for 
Did you mean: 

[2H_2023_ INT-15852] Default Port Value 22 Setting in Integration Center and Security Center

pboulicaut
Participant
0 Kudos

In 2H_2023 release, SAP is blocking the sftp port of sftp destinations to 22 in built-in integration tool

Integration Center

What used to be configurable, is now a fixed value.

How a customer who is having multiple integration with third party vendors having SFTP server on different port than 22 ( customer is not choosing these port , these is the third party vendor who does that)

are supposed to send their employee list from Integration Center ?

Are we supposed to use

Multiple Destinations

in Integration Center

which seems to not be impacted by these change or these will be changed as well in next release ?

But these workaround is only working if we do the move from

Single destination

To

Multiple destinations

In B2305 release ( before nov 17th)

i don't see the benefit from an end-user perspective, except that we are forced to move integration (simple or not) to cpi

Or drop the file on successfactors sftp server

And have a second job on a ETL platform ( different from integration center) to download the file on the target sftp server using a different port than 22

just because sap decided to remove a feature that was introduced several years ago to improve the self-service of the Integration Center feature.


as a reminder for SAP :

Changing the SFTP port would fall under “security through obscurity” which means that the security isn’t technically enhanced, but the SFTP port has been obscured and isn’t as easy for attackers to access. In practice, this means that the thousands of bots scanning the internet for open SFTP servers are a lot less likely to find yours.

pboulicaut
Participant
0 Kudos

karenperez do you have an idea about the security rational to block outgoing sftp destination to port 22 ?

it's totally out of customer control to choose which port number an outgoing sftp server will be accepting sftp call so i'm clueless why SAP have decided to ban the pencil feature at the port level (when it used to be an enhancement, not so long ago)

Accepted Solutions (0)

Answers (0)