Topic
Generating a file encryption key for SFTP uploads for new connections or expiring keys.
Description
Contact and asset SFTP upload files can be encrypted using a file encryption key. By default, the encryption key for both contact and asset uploads is downloaded as a GPG file.
A GPG key is compatible with both GPG and PGP formats for contact upload files. Contact upload files formatted as either GPG or PGP can be uploaded to the Manager Portal. Asset upload files must be encrypted in GPG format only before upload.
A file encryption key must be generated in the following scenarios:
- Initial setup of file encryption
- Existing encryption key is nearing expiration (encryption keys expire after three years)
The encryption key is used to encrypt CSV upload files that are transferred to Everbridge through SFTP and downloaded from the Manager Portal.
For additional file security, Signature Validation is available to verify that uploaded files are authentic, have not been modified, and originate from trusted sources. Signature Validation is optional and is disabled by default.
This feature is available for contact and asset uploads via API and SFTP. For more information, see this article: EBS: Signature Validation for Contact & Asset Uploads
An Account Administrator or Organization Administrator can generate a new encryption key using the steps below:
- Log in to the Manager Portal.
- Navigate to the appropriate location:
- For account-level contacts, go to Settings > Security > Upload Options > Secure FTP.
- For organization-level contacts, go to Settings > Organization > Contacts/Assets > Upload Options.
- For account-level contacts, go to Settings > Security > Upload Options > Secure FTP.
- Under File Encryption, ensure Encryption Status is set to "On".
- Select Generate a New Key.
- In the confirmation dialog, review the message indicating that the previous key will no longer work. Select Generate Key.
- Remove the previous key from the encryption application's keyring to prevent further use.
- Select Download to save the new key.
If you need to download the SSH key for the SFTP connection, see knowledge article EBS: How to Generate a File Encryption Key for Contact and/or Asset SFTP Uploads.