How uploads connect
For trials that transfer data over SFTP, AitriumOS sends the prepared, de-identified dataset directly from the workstation to the trial’s SFTP server. It connects on the port the trial organization configured, usually TCP 22.- This connection does not use a web (HTTP) proxy. A corporate proxy handles AitriumOS’s HTTPS traffic to Aitrium only. The workstation must be allowed to open the SFTP connection itself.
- It is separate from the “Can’t reach Aitrium” check. AitriumOS can connect to Aitrium normally while the trial’s SFTP server is still blocked, so check both.
- The trial’s SFTP server sees the site’s public IP address, not Aitrium’s. Some trial organizations only accept connections from addresses they have approved. See If the trial’s server restricts IP addresses.
Check an upload destination
Open Settings → Network in AitriumOS. The Upload destinations list shows each SFTP server your trials send data to, with its host and port, the latest result and when it was checked. Select Check now to test a destination immediately. You can check again 10 seconds after the previous check finishes.What a check does
A check is a handshake only. AitriumOS looks up the server’s address, opens a connection, confirms the server answers as an SSH server and agrees on encryption with it, then disconnects. A check never signs in, never uses the trial’s credentials and never transfers data. On the trial organization’s server it appears as a short connection that normally ends with the disconnect reasonAitriumOS reachability check.
Automatic checks
From AitriumOS 2.2.6, destinations are also checked automatically:- Daily. While AitriumOS is open, each destination is checked at most once a day per workstation, at a randomized time. The daily check is skipped when an upload or a connection test to that destination succeeded in the last 24 hours, because that already proved the connection works.
- Before a first submission. When you open a submission to a destination this workstation has never uploaded to, AitriumOS checks it, unless it was checked in the last hour.
- No automatic retries. A failed automatic check is not repeated until the next day. Select Check now after IT makes a change.
Who else sees the result
AitriumOS reports the latest result for each destination to Aitrium. The report includes the destination’s host and port, the result and when it was checked, plus the negotiated encryption algorithms and the server’s host key fingerprint after a successful check. It never includes credentials, patient data, file names, the workstation’s IP address or proxy details. These results appear in site readiness, so your organization’s administrators, the trial organization and Aitrium support can see when a destination is blocked. See Upload destination reachability.Transfer status on the trial dashboard
The trial dashboard header shows the trial’s data transfer status: Transfer connected, Transfer failed or Not checked yet. This is a full connection test: unlike a reachability check, it signs in with the trial’s credentials, but it transfers no data. Hover over the status to see the message and when it was checked, and select it to test again.What the messages mean
Upload destinations list
The examples below usesftp.example.org and port 22; AitriumOS shows your destination’s host and port. On macOS, messages name AitriumOS instead of AitriumOS (NewLeaf.exe).
Upload and connection test messages
These appear when an upload fails and in the trial dashboard’s transfer status. The transfer status shows the full message right after a test, and a one-line summary for a stored result, for example The server could not be reached from this workstation.Blocked from connecting to sftp.example.org:22 … Ask IT to allow outbound TCP 22 to sftp.example.org for AitriumOS (NewLeaf.exe).
Blocked from connecting to sftp.example.org:22 … Ask IT to allow outbound TCP 22 to sftp.example.org for AitriumOS (NewLeaf.exe).
No response from sftp.example.org:22 within 20s (TCP connect) …
No response from sftp.example.org:22 within 20s (TCP connect) …
No response from sftp.example.org:22 within 30s (SSH handshake) …
No response from sftp.example.org:22 within 30s (SSH handshake) …
Unable to connect to the SFTP server: the connection was refused or could not be made. Verify the host, port, and network access.
Unable to connect to the SFTP server: the connection was refused or could not be made. Verify the host, port, and network access.
The SFTP server's security settings aren't supported by this version of AitriumOS. Please update AitriumOS or contact Aitrium support.
The SFTP server's security settings aren't supported by this version of AitriumOS. Please update AitriumOS or contact Aitrium support.
Authentication failed. Verify the configured username and credentials.
Authentication failed. Verify the configured username and credentials.
Failed to fetch site integration credentials … / Transfer credentials are not available yet.
Failed to fetch site integration credentials … / Transfer credentials are not available yet.
OpenSSH format detected but ssh-keygen is not available for conversion.
OpenSSH format detected but ssh-keygen is not available for conversion.
ssh-keygen tool from Windows’ OpenSSH Client optional feature. Site IT can add OpenSSH Client under Optional features in Windows Settings, or the trial organization can supply the key in PEM format.PuTTY PPK format is not supported …
PuTTY PPK format is not supported …
.ppk format. The trial organization must export it in OpenSSH format with PuTTYgen and update the credentials.For site IT: allowing the connection
This section covers the SFTP upload only. For the rest of the workstation setup, including the HTTPS allowlist and proxy, see the IT setup checklist. If you operate the trial’s SFTP server rather than the site’s network, see SFTP server compatibility.- Allow outbound TCP to the host and port shown in Upload destinations. The connection goes directly from the workstation. It cannot go through a web (HTTP) proxy.
- Allow the program, not just the port. Endpoint-security products and per-application firewall rules often block one program while allowing another. Allow the AitriumOS executable:
- Windows, per-machine (MSI) install:
C:\Program Files\AitriumOS\NewLeaf.exe - Windows, per-user (Standard) install:
%LOCALAPPDATA%\AitriumOS\NewLeaf.exe - macOS: the AitriumOS application
- Windows, per-machine (MSI) install:
- If the host name has several addresses, such as an IPv6 and an IPv4 address, AitriumOS 2.2.7 tries each in turn within one time budget. A blocked IPv6 address therefore no longer stops an upload when the IPv4 address works. Allow every address you intend the workstation to use.
- Confirm with AitriumOS itself. Run Settings → Network → Upload destinations → Check now on the workstation after each change.
If the trial’s server restricts IP addresses
Some trial organizations only accept SFTP connections from IP addresses they have approved. The trial’s server sees your site’s public egress IP address: the address your network’s traffic leaves from, often shared by many workstations. It does not see the workstation’s internal address, and there is no Aitrium relay address to approve. Ask your network team for the public egress IP address, or addresses, used by the workstations running AitriumOS, and send them to the trial organization. A No response or refused the connection result that persists after your own firewall allows the connection usually means the address has not been approved yet.Getting help
Contact [email protected] with:- The exact message, and the result of Check now
- Your AitriumOS version, shown in the application header
- What IT has already allowed, for example the program, the host and port, and whether the trial organization has approved your public IP address