DataFlex
DataFlex
SFTP Set Allowed SSH Algorithms
See more SFTP Examples
Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.
Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.
Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.
Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
Handle hoSftp
Variant vJson
Handle hoJson
String sAllowed_kex
String sAllowed_hostKey
String sAllowed_cipher
String sAllowed_mac
Integer iPort
String sTemp1
Move False To iSuccess
// Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
// algorithms permitted for the connection. The only argument is a JsonObject. It must be
// called before Connect.
//
// -------------------------------------------------------------------------------------------
// Note: You typically should NOT explicitly set allowed algorithms.
// By default, Chilkat orders algorithms according to best practices and accounts for known
// vulnerabilities such as the "Terrapin Attack". Hard-coding algorithms can make an
// application brittle over time: if a server later changes its allowed algorithms, or if you
// connect to a different server, the client and server may fail to agree on a mutually
// supported set.
// -------------------------------------------------------------------------------------------
Get Create (RefClass(cComChilkatSFtp)) To hoSftp
If (Not(IsComObjectCreated(hoSftp))) Begin
Send CreateComObject of hoSftp
End
Get Create (RefClass(cComChilkatJsonObject)) To hoJson
If (Not(IsComObjectCreated(hoJson))) Begin
Send CreateComObject of hoJson
End
// The algorithms supported by Chilkat, by category:
//
// Key-exchange:
// curve25519-sha256
// curve25519-sha256@libssh.org
// ecdh-sha2-nistp256
// ecdh-sha2-nistp384
// ecdh-sha2-nistp521
// diffie-hellman-group14-sha256
// diffie-hellman-group16-sha512
// diffie-hellman-group18-sha512
// diffie-hellman-group-exchange-sha256
// diffie-hellman-group1-sha1
// diffie-hellman-group14-sha1
// diffie-hellman-group-exchange-sha1
//
// Host key:
// ssh-ed25519
// ecdsa-sha2-nistp256
// ecdsa-sha2-nistp384
// ecdsa-sha2-nistp521
// rsa-sha2-256
// rsa-sha2-512
// ssh-rsa
// ssh-dss
//
// Cipher (encryption):
// chacha20-poly1305@openssh.com
// aes128-ctr
// aes256-ctr
// aes192-ctr
// aes128-cbc
// aes256-cbc
// aes192-cbc
// aes128-gcm@openssh.com
// aes256-gcm@openssh.com
// twofish256-cbc
// twofish128-cbc
// blowfish-cbc
//
// MAC (hash):
// hmac-sha2-256
// hmac-sha2-512
// hmac-sha2-256-etm@openssh.com
// hmac-sha2-512-etm@openssh.com
// hmac-sha1-etm@openssh.com
// hmac-sha1
// hmac-ripemd160
// hmac-sha1-96
// hmac-md5
// List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
// order of preference.
Move "curve25519-sha256@libssh.org,ecdh-sha2-nistp256" To sAllowed_kex
Move "ssh-ed25519,ecdsa-sha2-nistp256" To sAllowed_hostKey
Move "chacha20-poly1305@openssh.com,aes256-ctr" To sAllowed_cipher
Move "hmac-sha2-256,hmac-sha2-512" To sAllowed_mac
Get ComUpdateString Of hoJson "kex" sAllowed_kex To iSuccess
Get ComUpdateString Of hoJson "hostKey" sAllowed_hostKey To iSuccess
Get ComUpdateString Of hoJson "cipher" sAllowed_cipher To iSuccess
Get ComUpdateString Of hoJson "mac" sAllowed_mac To iSuccess
// Apply the allow-list before connecting.
Get pvComObject of hoJson to vJson
Get ComSetAllowedAlgorithms Of hoSftp vJson To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoSftp To sTemp1
Showln sTemp1
Procedure_Return
End
Move 22 To iPort
Get ComConnect Of hoSftp "sftp.example.com" iPort To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoSftp To sTemp1
Showln sTemp1
Procedure_Return
End
Showln "Connected."
Send ComDisconnect To hoSftp
End_Procedure