Sample code for 30+ languages & platforms
DataFlex

SSH Host Key Fingerprint

See more SSH Examples

Demonstrates getting the SSH server's host key fingerprint after connecting. The HostKeyFingerprint property returns the classic MD5 form, while GetHostKeyFP returns a fingerprint using a chosen hash algorithm, with optional inclusion of the key type and hash name.

Background: The host key fingerprint identifies the server, and comparing it against a known-good value is how a client implements host-key pinning — detecting a man-in-the-middle or a server whose key has changed. This is the same fingerprint an SSH client shows on first connection when it asks whether to trust the host. Prefer SHA256, which is the modern standard; MD5 fingerprints still appear in older tooling but are cryptographically weak.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoSsh
    String sHostname
    Integer iPort
    String sMd5_fingerprint
    Boolean iIncludeKeyType
    Boolean iIncludeHashName
    String sSha256_fingerprint
    String sTemp1
    Boolean bTemp1

    Move False To iSuccess

    //  This example requires the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    //  Demonstrates getting the SSH server's host key fingerprint after connecting.

    Get Create (RefClass(cComChilkatSsh)) To hoSsh
    If (Not(IsComObjectCreated(hoSsh))) Begin
        Send CreateComObject of hoSsh
    End

    Move "ssh.example.com" To sHostname
    Move 22 To iPort
    Get ComConnect Of hoSsh sHostname iPort To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  The classic MD5 fingerprint is available as a property.
    Get ComHostKeyFingerprint Of hoSsh To sMd5_fingerprint
    Showln sMd5_fingerprint
    //  For example:  ssh-rsa 3072 21:b0:d8:41:4e:ef:78:10:20:af:01:b7:71:5d:eb:94

    //  GetHostKeyFP returns a fingerprint using the hash algorithm of your choice, such as SHA256,
    //  SHA384, or SHA512.  The 2nd and 3rd arguments control whether the key type and the hash name
    //  are included in the returned string.
    Move True To iIncludeKeyType
    Move True To iIncludeHashName
    Get ComGetHostKeyFP Of hoSsh "SHA256" iIncludeKeyType iIncludeHashName To sSha256_fingerprint
    Get ComLastMethodSuccess Of hoSsh To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln sSha256_fingerprint
    //  ssh-rsa SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

    Move False To iIncludeKeyType
    Move True To iIncludeHashName
    Get ComGetHostKeyFP Of hoSsh "SHA256" iIncludeKeyType iIncludeHashName To sSha256_fingerprint
    Get ComLastMethodSuccess Of hoSsh To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln sSha256_fingerprint
    //  SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

    Move True To iIncludeKeyType
    Move False To iIncludeHashName
    Get ComGetHostKeyFP Of hoSsh "SHA256" iIncludeKeyType iIncludeHashName To sSha256_fingerprint
    Get ComLastMethodSuccess Of hoSsh To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln sSha256_fingerprint
    //  ssh-rsa Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

    Move False To iIncludeKeyType
    Move False To iIncludeHashName
    Get ComGetHostKeyFP Of hoSsh "SHA256" iIncludeKeyType iIncludeHashName To sSha256_fingerprint
    Get ComLastMethodSuccess Of hoSsh To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln sSha256_fingerprint
    //  Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

    Send ComDisconnect To hoSsh


End_Procedure