SFTP file transfer with WSO2 ESB

  • By Heshan Suriyaarachchi
  • 11 Feb, 2011

The VFS transport implementation is based on Apache Commons VFS implementation. VFS (Virtual File System) transport implementation is a module which belongs to the Apache Synapse project. It has a set of service level parameters that needs to be specified for each service. VFS service level parameters and their descriptions can be found in [1] and the endpoint formats can be found in [2].

Following is a SFTP sample for ESB 3.0.1. It copies a file from one SFTP location to another SFTP folder. SFTPVFSProxy is the proxy service which copies file from one SFTP location to another.

Applies to:

Product WSO2 ESB 3.0.1

Create Directories in the SFTP server

Create the directories named "in", "out" and "original" in the SFTP Server.

NOTE: Remember to update the proxy service configuration with the paths of these directories.

Registering Transport Listener and Transport Sender

1). Uncomment the VFS Transport Listener from the axis2.xml (which resides in ESB_HOME/repository/conf/ directory)

 <transportReceiver name="vfs" class="org.apache.synapse.transport.vfs.VFSTransportListener"/>

2). Uncomment the VFS Transport Sender from the axis2.xml (which resides in ESB_HOME/repository/conf/ directory)

 <transportSender name="vfs" class="org.apache.synapse.transport.vfs.VFSTransportSender"/>

Proxy Configuration

1). Go to the ESB_HOME/bin and run the script which starts wso2server.
Eg. wso2server.bat for windows environments for linux environments

2). The server will then start. You can access the management console using the following URL [8].

3). Log into the Mangement Console using following credentials.
      username: admin
      password: admin

4). Select the Source View from the ESB Management Console and add the following proxy configuration to the Synapse configuration. 

NOTE: Remember to update the directory locations according to your SFTP server.

<proxy name="SFTPVFSProxy" transports="vfs" startOnLoad="true" xmlns="">
              <log level="full"/>
              <property name="File" expression="fn:concat('test-', get-property('transport', 'FILE_PATH'))" scope="default"/>
              <property name="transport.vfs.ReplyFileName" expression="fn:concat(fn:substring-after(get-property('MessageID'), 'urn:uuid:'), '.xml')" scope="transport"/>
              <property name="OUT_ONLY" value="true"/>
                  <endpoint name="endpoint_urn_uuid_A1546EFFD75FC9CCED785986339425964585275">
                      <address uri="vfs:sftp://heshan:password@"/>
      <parameter name="transport.vfs.ActionAfterProcess">MOVE</parameter>
      <parameter name="transport.PollInterval">15</parameter>
      <parameter name="transport.vfs.MoveAfterProcess">vfs:sftp://heshan:password@</parameter>
      <parameter name="transport.vfs.FileURI">vfs:sftp://heshan:password@</parameter>
      <parameter name="transport.vfs.MoveAfterFailure">vfs:sftp://heshan:password@</parameter>
      <parameter name="transport.vfs.FileNamePattern">.*.xml</parameter>
      <parameter name="transport.vfs.ContentType">application/xml</parameter>
      <parameter name="transport.vfs.ActionAfterFailure">MOVE</parameter>

Running the Sample

Copy the following XML (test.xml) file to the directory named "in" which is in your SFTP server. Then it will be moved to the directory named "out".

Following is the XML file (test.xml) that is being moved.

<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="" xmlns:wsa="">
       <getQuote xmlns="http://services.samples">


Resolving UnknownHostKey Exception

Earlier, we looked at how to do a SFTP file transfer with WSO2 ESB's Virtual File System (VFS) transport. When running the above sample, for example when we specified the VFS endpoint by giving the host name (instead of the IP address). Then, you might come across the following exception (UnknownHostKey).

Exception thrown in the command prompt;

[2010-01-19 22:03:58,336] ERROR - VFSTransportListener cannot resolve fileObject
org.apache.commons.vfs.FileSystemException: Could not connect to SFTP server at "sftp://user1:***".
        at org.apache.commons.vfs.provider.sftp.SftpFileProvider.doCreateFileSystem(
        at org.apache.commons.vfs.provider.AbstractOriginatingFileProvider.getFileSystem(
        at org.apache.commons.vfs.provider.AbstractOriginatingFileProvider.findFile(
        at org.apache.commons.vfs.provider.AbstractOriginatingFileProvider.findFile(
        at org.apache.commons.vfs.impl.DefaultFileSystemManager.resolveFile(
        at org.apache.commons.vfs.impl.DefaultFileSystemManager.resolveFile(
        at org.apache.commons.vfs.impl.DefaultFileSystemManager.resolveFile(
        at org.apache.synapse.transport.vfs.VFSTransportListener.scanFileOrDirectory(
        at org.apache.synapse.transport.vfs.VFSTransportListener.poll(
        at org.apache.synapse.transport.vfs.VFSTransportListener.poll(
        at org.apache.axis2.transport.base.AbstractPollingTransportListener$1$
        at org.apache.axis2.transport.base.threads.NativeWorkerPool$
        at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(
        at java.util.concurrent.ThreadPoolExecutor$
        at by: org.apache.commons.vfs.FileSystemException: Could not connect to SFTP server at "".
        at org.apache.commons.vfs.provider.sftp.SftpClientFactory.createConnection(
        at org.apache.commons.vfs.provider.sftp.SftpFileProvider.doCreateFileSystem(
        ... 14 more
Caused by: com.jcraft.jsch.JSchException: UnknownHostKey: DSA key fingerprint is 62:fb:a5:c7:1a:34:f4:05:7a:e8:06:b9:57:e5:de:e4
        at com.jcraft.jsch.Session.checkHost(
        at com.jcraft.jsch.Session.connect(
        at com.jcraft.jsch.Session.connect(
        at org.apache.commons.vfs.provider.sftp.SftpClientFactory.createConnection(
        ... 15 more


Apache Commons-VFS [2] uses JSCH [5] for its underlying SSH layer. JSCH uses the location $HOME/.ssh for the known_hosts file by default.
Eg. location is $HOMEPATH/.ssh

Therefore, since the host that you are trying to connect with is not in the known_hosts file, Synapse has no idea whether the SFTP hosts can be trusted. Therefore, we need to add the host to the known_hosts file.


1) Open SSH using the above location too by default.
2) If you open an SSH session in the target host, it will ask to add the credentials to this file. However, the session will fail as you should not have permission on an SFTP server to do this; but that is alright.
3) After the above modification, you now have the updated known_hosts file.

Now the SFTP sample will work with this host.


Configure your SFTP server with write_enable

The VFS transport uses a file locking mechanism to make sure that a single file is being processed by a single listener in a given situation. Therefore, the VFS transport will add a lock file and when the processing completes, it will remove the lock file. Therefore, it is mandatory to have the above mentioned property enabled in your SFTP server.

Eg. If the SFTP server that you are using is vsftpd [6], then set the write_enable property to "YES".

If you are interested in trying out more VFS samples, refer [3] and [4].

[1] -
[2] -
[3] -
[4] -
[5] -
[6] -
[7] -
[8] -