DataFlex
DataFlex
SSH Tunnel Authenticate with Password and Private Key
See more SSH Tunnel Examples
Demonstrates the Chilkat SshTunnel.AuthenticatePwPk method, which authenticates with a server that requires both a password and a private key. The arguments are the username, the password, and an SshKey private key.
Note: The private-key path is relative to the application's current working directory. Absolute paths may also be used. Supply the path to your own key file.
Background: Most servers require either a password or a public key, not both — but some high-security deployments mandate two-factor SSH. This method satisfies that policy in one call, combining something you know (the password) with something you have (the key). The password should come from a secure source rather than a literal.
Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
Handle hoTunnel
Integer iSshPort
String sPassword
Variant vPrivKey
Handle hoPrivKey
String sKeyText
Boolean iWaitForThreadExit
String sTemp1
Boolean bTemp1
Move False To iSuccess
// Demonstrates the SshTunnel.AuthenticatePwPk method, which authenticates with an SSH server that
// requires BOTH a password and a private key. The 1st argument is the username, the 2nd is the
// password, and the 3rd is an SshKey private key.
Get Create (RefClass(cComChilkatSshTunnel)) To hoTunnel
If (Not(IsComObjectCreated(hoTunnel))) Begin
Send CreateComObject of hoTunnel
End
// The tunnel forwards accepted local connections to this destination through the SSH server.
Set ComDestHostname Of hoTunnel To "db.internal.example.com"
Set ComDestPort Of hoTunnel To 5432
// Connect to the SSH server. This performs the TCP/proxy connection and SSH handshake, but
// does not authenticate yet.
Move 22 To iSshPort
Get ComConnect Of hoTunnel "ssh.example.com" iSshPort To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoTunnel To sTemp1
Showln sTemp1
Procedure_Return
End
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
Move "mySshPassword" To sPassword
// Load the SSH private key. LoadText reads the file's text, which is then imported.
Get Create (RefClass(cComChilkatSshKey)) To hoPrivKey
If (Not(IsComObjectCreated(hoPrivKey))) Begin
Send CreateComObject of hoPrivKey
End
Get ComLoadText Of hoPrivKey "qa_data/id_rsa" To sKeyText
Get ComLastMethodSuccess Of hoPrivKey To bTemp1
If (bTemp1 = False) Begin
Get ComLastErrorText Of hoPrivKey To sTemp1
Showln sTemp1
Procedure_Return
End
Get ComFromOpenSshPrivateKey Of hoPrivKey sKeyText To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoPrivKey To sTemp1
Showln sTemp1
Procedure_Return
End
Get pvComObject of hoPrivKey to vPrivKey
Get ComAuthenticatePwPk Of hoTunnel "mySshLogin" sPassword vPrivKey To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoTunnel To sTemp1
Showln sTemp1
Procedure_Return
End
Showln "Authenticated with a password and a private key."
// After authenticating, call BeginAccepting to start listening for local connections to forward.
Move True To iWaitForThreadExit
Get ComCloseTunnel Of hoTunnel iWaitForThreadExit To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoTunnel To sTemp1
Showln sTemp1
Procedure_Return
End
End_Procedure