FileZilla 3.60.0: Explicit TLS enforcement now mandatory – how to support legacy FTP servers?
0 reputation · 22 Nov 2022, 08:07 UTC
Goal
We need to verify that FileZilla 3.60.0’s new explicit TLS handling can be accommodated in a test environment without exposing production credentials.
Constraints
The test server does not advertise TLS support. Site Manager entries were previously configured with “Require explicit FTP over TLS” under the assumption that a fallback to plain FTP would occur automatically. After the 3.60.0 release, the client aborts the connection when the handshake fails, and the fallback option is hidden in the global Settings dialog.
Unresolved Decision
Should we enable the “Fallback to plain FTP on TLS failure” setting for all legacy sites, or adjust each Site Manager entry to “Use explicit FTP if available” and accept the new mandatory behavior?
Specific Questions
- Will enabling the global fallback option allow a Site Manager entry that still has “Require explicit FTP over TLS” to connect to a non‑TLS server without manual per‑site changes?
- Does disabling the explicit TLS requirement in the Site Manager UI alter the client’s ability to negotiate TLS on servers that do advertise it?
- What impact does the new mandatory enforcement have on automated scripts that rely on implicit TLS or plain FTP connections?