Frequently Asked Questions

The NearlyFreeSpeech.NET FAQ (*)

Uploading (*)

What is the connection information to upload files to my web site?

The username for SFTP and ssh access is not the same as your member login; it is based on both your member login and the site name. The password, however, is the same as your member password. The specifics are listed in the "SSH/SFTP Information" box on each site's information panel in our member interface.

To find this information:

  1. Visit the Sites panel to display your list of sites.
  2. Select the site's "short name" in the "Sites" table to display the details about the site you want to access.
  3. Find the box titled "SSH/SFTP Information."
  4. Locate the username row and the appropriate hostname row for the protocol you wish to use.

How do I upload my content to my site?

This question depends largely on what tools you are using to create and manage the content of your site. There are four primary approaches people use.

In all cases, you'll need to check the documentation for the program you are using for specific instructions, but at a minimum you will require the connection information for your site to upload successfully.

We do not provide any "built-in" web tools in our member interface for content authoring. Such tools tend to be very limited; they offer only basic functionality and tend to produce a whole lot of slop websites, especially if they offer "AI features." As such, they do not provide the sophisticated and powerful options expected by our members.

Can I access my web site via ssh?

Yes. To access a website via ssh, use the connection information.

The SSH key fingerprints for our ssh servers are in this FAQ entry.

SFTP and scp are supported. Port forwarding is supported but is only permitted for establishing secure remote connections to your MySQL database.

Important: Our ssh environment is provided solely for maintaining your website and is not to be used for any other purpose. This specifically prohibits using it for proxying, port forwarding, or anything similar. Automated access to the ssh server is likewise prohibited, with an exception allowing connections once per day for the purpose of making offsite backups.

What directory do I upload my web site's files to?

Uploading clients should automatically be in the correct folder after they connect. Do not change your software's default upload directory setting unless you are absolutely sure your client is getting it wrong.

If automatic detection isn't working and you can't figure out why, the correct directory is /home/public.

(Once uploaded, scripts that run on your site will use a different path to access your files, depending on whether they are PHP or CGI.)

What hostname should I use for SSH/SFTP?

To get the correct hostname to use for ssh/SFTP access to your site:

  1. Go to the Sites tab in the member interface.
  2. Select your site name from the list to go to its Site Information panel.
  3. On the Site Information panel, find the box titled "SSH/SFTP Information."
  4. The "SSH/SFTP Hostname" line will contain the exact hostname to use for SSH and SFTP.

How do I connect to the shell with ssh?

Most people use one of these three options:

Other options also exist, but are substantially less popular:

Once you have found or installed your ssh program, give it your connection information to get connected to your site hosted on our service. If you are using OpenSSH or a similar tool, the command looks something like:

ssh username_sitename@ssh.xyz1.nearlyfreespeech.net

Graphical tools vary widely; consult their documentation.

Once connected, you will get a shell prompt, which may look something like:

[example /home/public]$

Actual prompts can vary widely but tend to end in $ or %. To reflect these variations, in our documentation, we use:

YourPrompt$ echo "Hello, world!"

to indicate that you should type the command echo "Hello, world!" (but not the YourPrompt$ part) at your shell prompt, whatever it looks like.

Due to the variety of ssh options and the complexity of the Unix shell, the full details of their use are well beyond the scope of a FAQ. Many online tutorials exist, like this one. For a deeper dive, many community colleges offer continuing education classes covering one or both topics.

What is SFTP?

SFTP is the Secure File Transfer Protocol. It is sort of a hybrid between old-school (unsupported) FTP and ssh.

You can use SFTP to send files to our service. It's much safer and more private than regular FTP because it encrypts both your password and your file transfers.

Since SFTP piggybacks on the ssh protocol, SFTP is also robust in the face of NAT routers and firewalls.

Due to its advantages, SFTP is the recommended method for uploading content to your site.

There are a number of SFTP applications listed in our member wiki. (Note that "Secure FTP," which only supported SSL/TLS-encrypted FTP, will not work for accessing our servers via SFTP.)

Can I configure my ssh connection to use a public key?

Yes, but.

Our system does not access your site's filesystem until after you have authenticated yourself. Also, correct authentication depends on both member name and site (since more than one member name may have permission to access a given site and a given member name may be able to access more than one site). Therefore, you cannot place a public key file in your site's filesystem to bypass password authentication.

Instead, we keep a separate keychain for each member. To use an ssh public key, you can add it to your keychain on the profile tab.

Once installed into your membership's keychain, an ssh key will authenticate you for any site you are authorized to access, including your sites and any sites you may have adjunct access to.

Per current best security practices, here are the key types we support:

DSA/DSS ("ssh-dss") keys are not supported at all. This is a US government FIPS standard developed by the NSA and intended only for low-security usage. (Read: they are probably not secure.)

If you use an RSA key, you must use a client that supports RFC8332 for SHA-256 (rsa-sha2-256) and SHA-512 (rsa-sha2-512) signatures. As of 2021, our servers no longer accept RSA keys with SHA-1 signatures because they are demonstrably insecure. If you run into that issue, please update your OpenSSH client and/or consider switching to faster, safer Ed25519 keys.

What are the fingerprints for the NearlyFreeSpeech.NET ssh keys?

We publish SSHFP records for our SSH servers that should automate validating the keys, but if you need or want to check them, the current keys are:

ssh.nyc1.nearlyfreespeech.net

Ed25519
SHA256: 4ckOOn5g9ONLZ4M4LJo5VD4KkWaTNTMweFG1uHALdiQ
SHA1: J94RhbhbcuP3YmsYumIZxR67sW0
ECDSA
SHA256: LXAtpKd30Ooiom9Gr3RwN2h5fnSt67G1FpwkaXKUiWI
SHA1: 7HUsWZuksYyozAWGJULt6MyRrQk
RSA
SHA256: Tqgduo3qxVYyjBpTMU1tEyqmXhaob631e9Yb1XWsnIA
SHA1: RUFuJZmbDKcQ5A6+Hk+mXDkG2c4

ssh-verify.nearlyfreespeech.net (Only used during login recovery!)

Ed25519
SHA256: utxOHL0bVomfF5twrPCJGCnkhyeIYGyBk7IycC3f8xU
SHA1: r7meZXopDo1fOGzp6sh4s3KxRT0
ECDSA
SHA256: n+hiltOccg9L3g3z3DCfQy95gZyPJNpG/ppyU+/Dtg8
SHA1: 9sm339z3vdEFOM+jqAAa/ElYY+Y
RSA
SHA256: AcXGgQe1sW9NkzZwzIa+T6A8XwiLTXWj3cLcRZ5K33A
SHA1: oClq3MNF11ESISPbjPgLnPJEjH0

If your client is giving you key fingerprints in MD5 format, check your settings (e.g., FingerprintHash sha256) or update your ssh client. SSH server keys were last updated on 2025-05-19.

Is FTP supported for uploads?

No. Use SFTP or SCP instead.

FTP support was deprecated in 2010. FTP ceased working unexpectedly in June 2026, and we determined that fixing it was not viable.

What if I think the name of your ssh server is too long?

Easy way: You can use xyz1.nfsnssh.com instead of ssh.xyz1.nearlyfreespeech.net if you prefer.

Better way: OpenSSH allows the creation of nicknames. To use this feature, create (or edit) the file ~/.ssh/config (on the client machine you will be connecting from, not ours!) and add content like this:

Host nfsnssh
        Hostname ssh.xyz1.nearlyfreespeech.net
        Port 22

With this done, you can use "nfsnssh" as if it were a hostname in ssh, scp, and sftp. For example, just use ssh mylogin_mysite@nfsnssh to connect to mysite as mylogin.

You can even use the User option to create per-site nicknames to make commands even shorter:

Host *_nfsn
        Hostname ssh.xyz1.nearlyfreespeech.net
        Port 22

Host mysite_nfsn
        User mylogin_mysite

Host othersite_nfsn
        User mylogin_othersite
Then you just ssh mysite_nfsn to connect to mysite and ssh othersite_nfsn to connect to othersite. It doesn't get much shorter than that! See the ssh_config man page for complete details.

If you don't happen to be using OpenSSH, many other ssh tools offer similar options, many with graphical interfaces that make establishing a connection as simple as clicking, regardless of the hostname.

I can connect to NearlyFreeSpeech.NET just fine, so why is your SFTP or ssh server unreachable or timing out?

The first thing to check is to make sure you are using the correct connection information for your site, including your username and password as well as the correct name of the server for the service you are trying to use. You should always check this, even if you are sure it is correct, before exploring more exotic options.

If you are unable to connect at all, or if the connection appears to drop immediately, one possible explanation for this is that you are running firewall software (or have a hardware firewall) that is blocking your connection.

If you use file sharing software, many "P2P block list" applications can block connections to us.

In such cases you will need to either disable the application or set up a manual override to allow the connection.

The most common diagnostics that indicate problems with firewalls and blocking software are "Permission Denied," "No route to host," "Connection refused," "Host unreachable," or "General failure" when attempting to access our SSH/SFTP servers, but no similar problem when trying to access your site(s) or ours by HTTP or HTTPS. If you can't access anything at all, the problem is likely something else.

This can also happen if you have non-functional IPv6 connectivity. Our ssh server supports IPv6 and some home network devices advertise IPv6 capability even if it is not supported by your ISP.

Is automated SSH/SFTP access to the system allowed?

Any automated SSH/SFTP access must use a public key. No hardcoded passwords!

As long as you are physically initiating uploads or downloads yourself you're fine, even if an automated component is involved. (Just make sure you're either using a key or typing the password by hand.)

Unattended or automated SSH/SFTP access is allowed only for these purposes:

If you want automatic unattended uploads beyond these limits, you should use HTTP POST or PUT requests and a small script on your site to receive the files.

Please respect the shared resources used by SSH—which we currently do not charge for—by observing these guidelines. If you have any questions about what is allowable, please ask.