An Azure service for ingesting, preparing, and transforming data at scale.
Hello @Shivata Tikoo ,
Thank you for sharing the details of the Azure Data Factory (ADF) SFTP connectivity issue.
Based on our analysis, the connection failure is occurring during the SSH handshake phase due to a host key algorithm compatibility mismatch between Azure Data Factory and the target SFTP server.
The target SFTP server is configured to support only the modern SSH host key signature algorithms rsa-sha2-256 and rsa-sha2-512. According to Microsoft guidance, the Azure Data Factory SFTP connector currently does not support these host key signature algorithms, resulting in the failure of SSH algorithm negotiation before authentication can occur. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Recommended Mitigation
Validate Alternative Host Key Algorithm Support
- Engage the SFTP provider to determine whether a compatible host key algorithm (such as ssh-rsa) can be temporarily enabled for Azure Data Factory connectivity testing.
- Implement a Self-Hosted Integration Runtime (Recommended)
- Deploy a Self-Hosted Integration Runtime (SHIR) on a Windows or Linux server.
- Utilize a modern SFTP client such as OpenSSH, WinSCP, PowerShell SFTP modules, or Python-based SFTP libraries that support rsa-sha2-256 and rsa-sha2-512 algorithms. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
- Transfer files from the partner SFTP server to Azure Blob Storage or Azure Data Lake Storage Gen2. - Continue using Azure Data Factory for orchestration, ingestion, transformation, and downstream processing. ```1. Product Enhancement Request - If direct connectivity through the native Azure Data Factory SFTP connector is a business requirement, we recommend raising a Microsoft Support request and submitting product feedback requesting support for rsa-sha2-256 and rsa-sha2-512 host key signature algorithms. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Conclusion
At present, this behavior appears to be a product limitation of the Azure Data Factory SFTP connector rather than an issue with networking, firewall rules, authentication credentials, or server configuration. The most reliable and Microsoft-recommended workaround is to leverage a Self-Hosted Integration Runtime with a modern SFTP client that supports rsa-sha2 host key algorithms and use Azure Storage as the intermediate staging layer. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Please let us know if you would like assistance designing or implementing the SHIR-based solution.Hello @Shivata Tikoo ,
Thank you for sharing the details of the Azure Data Factory (ADF) SFTP connectivity issue.
Based on our analysis, the connection failure is occurring during the SSH handshake phase due to a host key algorithm compatibility mismatch between Azure Data Factory and the target SFTP server.
The target SFTP server is configured to support only the modern SSH host key signature algorithms rsa-sha2-256 and rsa-sha2-512. According to Microsoft guidance, the Azure Data Factory SFTP connector currently does not support these host key signature algorithms, resulting in the failure of SSH algorithm negotiation before authentication can occur. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Recommended Mitigation
Validate Alternative Host Key Algorithm Support
- Engage the SFTP provider to determine whether a compatible host key algorithm (such as ssh-rsa) can be temporarily enabled for Azure Data Factory connectivity testing.
- Implement a Self-Hosted Integration Runtime (Recommended)
- Deploy a Self-Hosted Integration Runtime (SHIR) on a Windows or Linux server.
- Utilize a modern SFTP client such as OpenSSH, WinSCP, PowerShell SFTP modules, or Python-based SFTP libraries that support rsa-sha2-256 and rsa-sha2-512 algorithms. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
- Transfer files from the partner SFTP server to Azure Blob Storage or Azure Data Lake Storage Gen2. - Continue using Azure Data Factory for orchestration, ingestion, transformation, and downstream processing. ```1. Product Enhancement Request - If direct connectivity through the native Azure Data Factory SFTP connector is a business requirement, we recommend raising a Microsoft Support request and submitting product feedback requesting support for rsa-sha2-256 and rsa-sha2-512 host key signature algorithms. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Conclusion
At present, this behavior appears to be a product limitation of the Azure Data Factory SFTP connector rather than an issue with networking, firewall rules, authentication credentials, or server configuration. The most reliable and Microsoft-recommended workaround is to leverage a Self-Hosted Integration Runtime with a modern SFTP client that supports rsa-sha2 host key algorithms and use Azure Storage as the intermediate staging layer. SFTP connection problem from Azure Data Factory to a server that only supports rsa-sha2-256/512
Please let us know if you would like assistance designing or implementing the SHIR-based solution.