C
C
Continue SSH Tunnel Keyboard-Interactive Authentication
See more SSH Tunnel Examples
Demonstrates the Chilkat SshTunnel.ContinueKeyboardAuth method, which submits a response to a keyboard-interactive prompt. The only argument is the response text; for a request with multiple prompts, an XML response is supplied instead. It returns XML indicating the next prompt or the final result.
Background: This is the second half of the exchange started by
StartKeyboardAuth. A server may issue several rounds of prompts, so a robust client loops: submit answers, read the returned XML, and continue until it sees success or failure. On success, BeginAccepting still must be called before the tunnel forwards traffic.Chilkat C Downloads
#include <C_CkSshTunnel.h>
void ChilkatSample(void)
{
BOOL success;
HCkSshTunnel tunnel;
int sshPort;
const char *infoRequestXml;
const char *password;
const char *result;
BOOL waitForThreadExit;
success = FALSE;
// Demonstrates the SshTunnel.ContinueKeyboardAuth method, which submits a response to a
// keyboard-interactive prompt. The only argument is the response. For multiple prompts, an XML
// response is supplied instead.
tunnel = CkSshTunnel_Create();
// The tunnel forwards accepted local connections to this destination through the SSH server.
CkSshTunnel_putDestHostname(tunnel,"db.internal.example.com");
CkSshTunnel_putDestPort(tunnel,5432);
// Connect to the SSH server. This performs the TCP/proxy connection and SSH handshake, but
// does not authenticate yet.
sshPort = 22;
success = CkSshTunnel_Connect(tunnel,"ssh.example.com",sshPort);
if (success == FALSE) {
printf("%s\n",CkSshTunnel_lastErrorText(tunnel));
CkSshTunnel_Dispose(tunnel);
return;
}
// Begin keyboard-interactive authentication to receive the server's prompt(s).
infoRequestXml = CkSshTunnel_startKeyboardAuth(tunnel,"mySshLogin");
if (CkSshTunnel_getLastMethodSuccess(tunnel) == FALSE) {
printf("%s\n",CkSshTunnel_lastErrorText(tunnel));
CkSshTunnel_Dispose(tunnel);
return;
}
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
password = "mySshPassword";
// Submit the response (typically the password). The returned XML indicates the next prompt or
// the final result.
result = CkSshTunnel_continueKeyboardAuth(tunnel,password);
if (CkSshTunnel_getLastMethodSuccess(tunnel) == FALSE) {
printf("%s\n",CkSshTunnel_lastErrorText(tunnel));
CkSshTunnel_Dispose(tunnel);
return;
}
printf("%s\n",result);
waitForThreadExit = TRUE;
success = CkSshTunnel_CloseTunnel(tunnel,waitForThreadExit);
if (success == FALSE) {
printf("%s\n",CkSshTunnel_lastErrorText(tunnel));
CkSshTunnel_Dispose(tunnel);
return;
}
CkSshTunnel_Dispose(tunnel);
}