Sample code for 30+ languages & platforms
C

SFTP Set Allowed SSH Algorithms

See more SFTP Examples

Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.

Chilkat C Downloads

C
#include <C_CkSFtp.h>
#include <C_CkJsonObject.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkSFtp sftp;
    HCkJsonObject json;
    const char *allowed_kex;
    const char *allowed_hostKey;
    const char *allowed_cipher;
    const char *allowed_mac;
    int port;

    success = FALSE;

    //  Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
    //  algorithms permitted for the connection.  The only argument is a JsonObject.  It must be
    //  called before Connect.
    //  
    //  -------------------------------------------------------------------------------------------
    //  Note: You typically should NOT explicitly set allowed algorithms.
    //  By default, Chilkat orders algorithms according to best practices and accounts for known
    //  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms can make an
    //  application brittle over time: if a server later changes its allowed algorithms, or if you
    //  connect to a different server, the client and server may fail to agree on a mutually
    //  supported set.
    //  -------------------------------------------------------------------------------------------

    sftp = CkSFtp_Create();

    json = CkJsonObject_Create();

    //  The algorithms supported by Chilkat, by category:
    //  
    //  Key-exchange:
    //    curve25519-sha256
    //    curve25519-sha256@libssh.org
    //    ecdh-sha2-nistp256
    //    ecdh-sha2-nistp384
    //    ecdh-sha2-nistp521
    //    diffie-hellman-group14-sha256
    //    diffie-hellman-group16-sha512
    //    diffie-hellman-group18-sha512
    //    diffie-hellman-group-exchange-sha256
    //    diffie-hellman-group1-sha1
    //    diffie-hellman-group14-sha1
    //    diffie-hellman-group-exchange-sha1
    //  
    //  Host key:
    //    ssh-ed25519
    //    ecdsa-sha2-nistp256
    //    ecdsa-sha2-nistp384
    //    ecdsa-sha2-nistp521
    //    rsa-sha2-256
    //    rsa-sha2-512
    //    ssh-rsa
    //    ssh-dss
    //  
    //  Cipher (encryption):
    //    chacha20-poly1305@openssh.com
    //    aes128-ctr
    //    aes256-ctr
    //    aes192-ctr
    //    aes128-cbc
    //    aes256-cbc
    //    aes192-cbc
    //    aes128-gcm@openssh.com
    //    aes256-gcm@openssh.com
    //    twofish256-cbc
    //    twofish128-cbc
    //    blowfish-cbc
    //  
    //  MAC (hash):
    //    hmac-sha2-256
    //    hmac-sha2-512
    //    hmac-sha2-256-etm@openssh.com
    //    hmac-sha2-512-etm@openssh.com
    //    hmac-sha1-etm@openssh.com
    //    hmac-sha1
    //    hmac-ripemd160
    //    hmac-sha1-96
    //    hmac-md5

    //  List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
    //  order of preference.
    allowed_kex = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256";
    allowed_hostKey = "ssh-ed25519,ecdsa-sha2-nistp256";
    allowed_cipher = "chacha20-poly1305@openssh.com,aes256-ctr";
    allowed_mac = "hmac-sha2-256,hmac-sha2-512";

    CkJsonObject_UpdateString(json,"kex",allowed_kex);
    CkJsonObject_UpdateString(json,"hostKey",allowed_hostKey);
    CkJsonObject_UpdateString(json,"cipher",allowed_cipher);
    CkJsonObject_UpdateString(json,"mac",allowed_mac);

    //  Apply the allow-list before connecting.
    success = CkSFtp_SetAllowedAlgorithms(sftp,json);
    if (success == FALSE) {
        printf("%s\n",CkSFtp_lastErrorText(sftp));
        CkSFtp_Dispose(sftp);
        CkJsonObject_Dispose(json);
        return;
    }

    port = 22;
    success = CkSFtp_Connect(sftp,"sftp.example.com",port);
    if (success == FALSE) {
        printf("%s\n",CkSFtp_lastErrorText(sftp));
        CkSFtp_Dispose(sftp);
        CkJsonObject_Dispose(json);
        return;
    }

    printf("Connected.\n");

    CkSFtp_Disconnect(sftp);


    CkSFtp_Dispose(sftp);
    CkJsonObject_Dispose(json);

    }