DataFlex
DataFlex
SFTP Authenticate with a SecureString Password and Private Key
See more SFTP Examples
Demonstrates the Chilkat SFtp.AuthenticateSecPwPk method, which authenticates using SecureString login and password objects together with a private key. The third argument is the SshKey private key.
Note: The private-key path is relative to the application's current working directory. Supply the path to your own key file.
Background: This is the
SecureString form of two-factor SFTP authentication: the password is held encrypted in memory and combined with a private key for servers that require both. It is the most protective option when a deployment mandates two-factor SSH and you also want to minimize plaintext credential exposure in the process.Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
Handle hoSftp
Integer iPort
String sPassword
Variant vPrivKey
Handle hoPrivKey
String sKeyText
Variant vSecureLogin
Handle hoSecureLogin
Variant vSecurePassword
Handle hoSecurePassword
String sTemp1
Boolean bTemp1
Move False To iSuccess
// Demonstrates the SFtp.AuthenticateSecPwPk method, which authenticates using SecureString login
// and password objects together with a private key. The 1st argument is the username, the 2nd
// is the password, and the 3rd is an SshKey private key.
Get Create (RefClass(cComChilkatSFtp)) To hoSftp
If (Not(IsComObjectCreated(hoSftp))) Begin
Send CreateComObject of hoSftp
End
// Step 1: Connect the SSH transport. Port 22 is the usual port.
Move 22 To iPort
Get ComConnect Of hoSftp "sftp.example.com" iPort To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoSftp To sTemp1
Showln sTemp1
Procedure_Return
End
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
Move "mySshPassword" To sPassword
// Load the SSH private key. LoadText reads the file's text, which is then imported.
Get Create (RefClass(cComChilkatSshKey)) To hoPrivKey
If (Not(IsComObjectCreated(hoPrivKey))) Begin
Send CreateComObject of hoPrivKey
End
Get ComLoadText Of hoPrivKey "qa_data/id_rsa" To sKeyText
Get ComLastMethodSuccess Of hoPrivKey To bTemp1
If (bTemp1 = False) Begin
Get ComLastErrorText Of hoPrivKey To sTemp1
Showln sTemp1
Procedure_Return
End
Get ComFromOpenSshPrivateKey Of hoPrivKey sKeyText To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoPrivKey To sTemp1
Showln sTemp1
Procedure_Return
End
// Place the login and password into SecureString objects.
Get Create (RefClass(cComChilkatSecureString)) To hoSecureLogin
If (Not(IsComObjectCreated(hoSecureLogin))) Begin
Send CreateComObject of hoSecureLogin
End
Get ComAppend Of hoSecureLogin "mySshLogin" To iSuccess
Get Create (RefClass(cComChilkatSecureString)) To hoSecurePassword
If (Not(IsComObjectCreated(hoSecurePassword))) Begin
Send CreateComObject of hoSecurePassword
End
Get ComAppend Of hoSecurePassword sPassword To iSuccess
Get pvComObject of hoSecureLogin to vSecureLogin
Get pvComObject of hoSecurePassword to vSecurePassword
Get pvComObject of hoPrivKey to vPrivKey
Get ComAuthenticateSecPwPk Of hoSftp vSecureLogin vSecurePassword vPrivKey To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoSftp To sTemp1
Showln sTemp1
Procedure_Return
End
// Step 3: Open the SFTP subsystem. This must be done after authentication and before any
// file or directory operations.
Get ComInitializeSftp Of hoSftp To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoSftp To sTemp1
Showln sTemp1
Procedure_Return
End
Showln "Authenticated."
Send ComDisconnect To hoSftp
End_Procedure