Sample code for 30+ languages & platforms
DataFlex

SSH Set Allowed Algorithms

See more SSH Examples

Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories, in order of preference, and is applied before connecting.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities such as the Terrapin attack.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm, or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old device. Otherwise the safer default is to let the library's ordering evolve as cryptographic guidance changes.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoSsh
    Variant vJson
    Handle hoJson
    String sAllowed_kex
    String sAllowed_hostKey
    String sAllowed_cipher
    String sAllowed_mac
    Integer iPort
    String sTemp1

    Move False To iSuccess

    //  This example requires the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    //  Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation.
    //  
    //  -------------------------------------------------------------------------------------------
    //  Note: You typically should NOT explicitly set allowed algorithms.
    //  By default, Chilkat orders algorithms according to best practices and accounts for known
    //  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms makes an application
    //  brittle over time: if a server later changes its allowed algorithms, or if you connect to a
    //  different server, the client and server may fail to agree on a mutually supported set.
    //  -------------------------------------------------------------------------------------------

    Get Create (RefClass(cComChilkatSsh)) To hoSsh
    If (Not(IsComObjectCreated(hoSsh))) Begin
        Send CreateComObject of hoSsh
    End

    Get Create (RefClass(cComChilkatJsonObject)) To hoJson
    If (Not(IsComObjectCreated(hoJson))) Begin
        Send CreateComObject of hoJson
    End

    //  Algorithms supported by Chilkat, by category:
    //  
    //  Key-exchange:  curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256,
    //    ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group14-sha256,
    //    diffie-hellman-group16-sha512, diffie-hellman-group18-sha512,
    //    diffie-hellman-group-exchange-sha256, diffie-hellman-group1-sha1,
    //    diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1
    //  
    //  Host key:  ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521,
    //    rsa-sha2-256, rsa-sha2-512, ssh-rsa, ssh-dss
    //  
    //  Cipher:  chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes192-ctr, aes128-cbc,
    //    aes256-cbc, aes192-cbc, aes128-gcm@openssh.com, aes256-gcm@openssh.com, twofish256-cbc,
    //    twofish128-cbc, blowfish-cbc
    //  
    //  MAC:  hmac-sha2-256, hmac-sha2-512, hmac-sha2-256-etm@openssh.com,
    //    hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, hmac-sha1, hmac-ripemd160,
    //    hmac-sha1-96, hmac-md5

    //  List the allowed algorithms for each category, in order of preference.
    Move "curve25519-sha256@libssh.org,ecdh-sha2-nistp256" To sAllowed_kex
    Move "ssh-ed25519,ecdsa-sha2-nistp256" To sAllowed_hostKey
    Move "chacha20-poly1305@openssh.com,aes256-ctr" To sAllowed_cipher
    Move "hmac-sha2-256,hmac-sha2-512" To sAllowed_mac

    Get ComUpdateString Of hoJson "kex" sAllowed_kex To iSuccess
    Get ComUpdateString Of hoJson "hostKey" sAllowed_hostKey To iSuccess
    Get ComUpdateString Of hoJson "cipher" sAllowed_cipher To iSuccess
    Get ComUpdateString Of hoJson "mac" sAllowed_mac To iSuccess

    //  Apply the allow-list.  This must be done before connecting.
    Get pvComObject of hoJson to vJson
    Get ComSetAllowedAlgorithms Of hoSsh vJson To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Move 22 To iPort
    Get ComConnect Of hoSsh "ssh.example.com" iPort To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoSsh To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln "Connected."

    Send ComDisconnect To hoSsh


End_Procedure