Tech Talks: SFTP Data Integration – From WinSCP to SSH.NET
Join Chris Gerello, Tom Linton, and Matt Kerslake as they explore OneStream’s SFTP integration evolution from WinSCP to SSH.NET—an architectural shift that delivers faster, cleaner, and more reliable execution. This transition removes legacy dependencies and positions the platform for a more flexible, future‑ready design.
Key Topics Covered
- Data integration planning considerations: data source identification, volume management, refresh frequency, and end-user data needs — the foundational questions before choosing an integration approach
- WinSCP limitations: required a separate executable installed on the machine, ran on the legacy .NET Framework (no longer supported by Microsoft), and was restricted to Windows operating systems only
- Version evolution: 7x and 8x both used WinSCP with Windows-only constraints; version 9x introduces SSH.NET, packaged directly with OneStream and integrated into .NET code — no separate executable required
- SSH.NET in version 9: implemented as a .NET package rather than a standalone program, runs on the current supported .NET framework, and removes the Windows-only restriction — opening the door to potential Linux support in future versions
- Microsoft alignment: OneStream's approach follows the natural evolution of Microsoft's .NET ecosystem, moving from the legacy .NET Framework to the modern, supported .NET platform
- Free migration service: OneStream's remote consulting team migrates WinSCP code to SSH.NET at no charge; turnaround is typically a few days with testing; existing WinSCP rules continue to function during the migration period with no end-user downtime
- Migration process: customer ships WinSCP rules to OneStream, team converts and tests offline, sends back for customer validation in dev, then moves to production
- Live demo: side-by-side comparison of WinSCP extensibility rule vs. SSH.NET equivalent in OneStream, including reference assembly and DLL configuration differences
- Smart Integration Connector (SIC): end-to-end encrypted replacement for legacy VPN-based connectivity; credentials remain locally hosted at the customer site; communication routed through Azure Relay service
- SIC feedback from the field: described as seamless, secure, easy to manage once set up, and a light lift for IT teams — an underrated feature of the platform
- SIC consultation service: dedicated SIC team offers consultations to help customers get stood up; recommended for any customer still relying on VPN for data connectivity
- Application management best practices: keep a blank application as a clean starting point; copy applications to create dev or training environments; use application history for change control
- Resources: Navigator courses on basics of inbound data integration and the Smart Integration Connector; Tech Talks After Hours episodes on data integration topics

