Sample code for 30+ languages & platforms
AutoIt

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat AutoIt Downloads

AutoIt
Local $bSuccess = False

;  This example requires the Chilkat API to have been previously unlocked.
;  See Global Unlock Sample for sample code.

;  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
;  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

$oSsh = ObjCreate("Chilkat.Ssh")

$oSsh.ConnectTimeoutMs = 5000
$oSsh.ReadTimeoutMs = 15000

Local $sHostname = "ssh.example.com"
Local $iPort = 22
$bSuccess = $oSsh.Connect($sHostname,$iPort)
If ($bSuccess = False) Then
    ConsoleWrite($oSsh.LastErrorText & @CRLF)
    Exit
EndIf

;  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
Local $sXmlResponse = $oSsh.StartKeyboardAuth("mySshLogin")
If ($oSsh.LastMethodSuccess = False) Then
    ConsoleWrite($oSsh.LastErrorText & @CRLF)
    Exit
EndIf

;  If the server sent a user authentication banner, an application may display it before
;  prompting.
ConsoleWrite("UserAuthBanner: " & $oSsh.UserAuthBanner & @CRLF)

$oXml = ObjCreate("Chilkat.Xml")
$bSuccess = $oXml.LoadXml($sXmlResponse)
If ($bSuccess = False) Then
    ConsoleWrite($oXml.LastErrorText & @CRLF)
    Exit
EndIf

;  Authentication is complete when the XML contains either a "success" or an "error" node.
If ($oXml.HasChildWithTag("success")) Then
    ConsoleWrite("No password required, already authenticated." & @CRLF)
    Exit
EndIf

If ($oXml.HasChildWithTag("error")) Then
    ConsoleWrite("Authentication failed." & @CRLF)
    Exit
EndIf

;  Normally you would not hard-code the password in source.  You should instead obtain it
;  from an interactive prompt, environment variable, or a secrets vault.
Local $sPassword = "mySshPassword"

;  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
;  prompts, so a robust client loops until it sees "success" or "error".
$sXmlResponse = $oSsh.ContinueKeyboardAuth($sPassword)
If ($oSsh.LastMethodSuccess = False) Then
    ConsoleWrite($oSsh.LastErrorText & @CRLF)
    Exit
EndIf

$bSuccess = $oXml.LoadXml($sXmlResponse)
If ($bSuccess = False) Then
    ConsoleWrite($oXml.LastErrorText & @CRLF)
    Exit
EndIf

If ($oXml.HasChildWithTag("success")) Then
    ConsoleWrite("SSH keyboard-interactive authentication successful." & @CRLF)
    Exit
EndIf

If ($oXml.HasChildWithTag("error")) Then
    ConsoleWrite("Authentication failed." & @CRLF)
EndIf