Updated on November 20, 2024

Overview

J.P. Morgan Host-to-Host is communications & security platform used for file transmission that supports internet connectivity for external clients to send bulk payments or receive reporting files using SFTP, HTTPS, and AS2 protocols.

Upcoming Events

Production Maintenance Window change
October 1, 2024

Effective October 1, 2024 the Production maintenance window has changed to:
Saturday 5:00 p.m. ET – Sunday 1:00 a.m. ET

For more information, please visit our H2H Recommended Best Practices.

Certificate Authority Change 2025

J.P. Morgan Host-to-Host has changed Certificate Authorities from Entrust to DigiCert.  All new new certificates will now be issued by DigiCert.  This will include new DigiCert Root and Intermediate certificates.

SFTP SSH Key Replacement1Q2025

Our SSH Key for the SFTP Protocol will be replaced on February 8, 2025, as the old key will expire. The new key will be available for download on our H2H SSH Support after February 3.

FTPS SSL Certificate Replacement
1Q2025

Our SSL certificate for the FTPS protocol will be replaced in February 8, 2025, as the old certificate is expiring. The new certificate will be available for download on our H2H SSL Support page after February 3. Please note that DigiCert will be the new Certificate Authority issuing these certificates (previously Entrust).

SSL AS2, HTTPS, NDM Certificate Replacement2Q2025

Our SSL certificate for the AS2, HTTPS, NDM protocols will be replaced in 2Q2025, as the old certificates will expire.  The new certificates will be available for download on our H2H SSL Support. Please note that DigiCert will be the new Certificate Authority issuing these certificates (previously Entrust).

Transport Authentication Key requirement update 2Q2025

Beginning in 2Q2025, all transport authentication keys and certificates must have a finite validity period of 1 year or less. For SSH keys, we will install renewal keys for a 1 year usage period.

SSH Cipher Deprecation2Q2025

Beginning in 2Q2025, CTR ciphers for SSH protocol will no longer be supported. For more information please visit our H2H SSH Support page.

PGP Key Replacement 3Q2025

Our PGP key will be replaced in 3Q2025. The new key will be available for download from our H2H PGP Support page.

  • All keys used with file transmission must expire in 2 years or less. All expiring keys must be renewed with unique and newly created keys and not previously used. There are no exceptions to this policy.
  • Beginning in 2Q2025 all transport authentication keys and certificates must expire in 1 year or less.

  • Transport Layer Security version 1.2 (TLSv1.2) is the minimum standard for communication session encryption for the following applications and protocols:
    • Applicability Statement 2 (AS2)
    • Hypertext Transfer Protocol Secure (HTTPS)
    • File Transport Protocol Secure (FTPS) – No longer supported for new setups
    • NDM via IBM® Sterling Connect:Direct® with Secure+®
  • The Administrative Procedures for Certificates include the following standards:
    • All certificates and keys must have a finite validity period of two years or less.
      • Beginning in 2Q2025, all certificates and keys used for transport authentication must have a finite validity period of 1 year or less.
    • No certificate shall be accepted unless it adheres, at minimum, to the following cryptographic specification:
      • Message digest: SHA-256, AES256
      • Asymmetric algorithm: RSA, DSS (DSS is not supported for SSH protocols).
      • Asymmetric algorithm key length: 2048 bits or more.
      • Elliptical curve algorithms are not supported at this time.
    • Elliptical curve algorithms are not supported at this time.

Certificates, Keys and Ciphers

Find everything you need, from bank security credentials to supports cryptography settings, to ensure your systems are compatible with J.P. Morgan Host-to-Host.
 

H2H PGP Support>

H2H SSH Support>

H2H SSL Support>

  • true

    Partner Key Management
    The PKM process is used by clients to submit their production security credentials for renewal.

    Learn more

  • true

    Best Practices
    Review best practices to help keep file transmissions reliable and secure and ensure the best experience.

    Learn more

  • true

    Client Acceptance Testing (CAT)
    Test and verify connectivity using our CAT, also known as UAT, environment.

    Learn more

  • true

    H2H Resiliency
    Configure your system to use DNS and short-lived IP caching.

    Learn more


Support

Questions? Contact our support team at 978-805-1200 or HosttoHost.helpdesk@jpmorgan.com. Representatives are available to assist you 24 hours a day, Monday through Friday. Government, municipal and public sector clients should call 844-718-0643

Please note the support team cannot advise clients on specific actions needed to make the required system changes. Clients should contact the application vendors for this information.

All trademarks, trade names and service marks appearing herein are the property of their respective owners.