Sample code for 30+ languages & platforms
Delphi ActiveX

Authenticate an SSH Tunnel with a Private Key

See more POP3 Examples

Demonstrates the Chilkat MailMan.SshAuthenticatePk method, which authenticates with the SSH server using public-key authentication after an SSH tunnel has been opened. The first argument is the SSH account name and the second is the SSH private key (an SshKey object). This example opens a tunnel, loads an OpenSSH private key, authenticates with it, and runs a POP3 operation through the tunnel.

Background: SSH public-key authentication replaces a password with a key pair: the public key is installed on the SSH server, and the client proves it holds the matching private key without ever transmitting a secret. This is the preferred method for automated systems — there is no password to embed or rotate, and the key can be revoked server-side. Chilkat reads the key with an SshKey object, which understands common formats such as OpenSSH and PuTTY.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
var
success: Integer;
mailman: TChilkatMailMan;
sshKey: TChilkatSshKey;
keyText: WideString;
count: Integer;

begin
success := 0;

//  Demonstrates the MailMan.SshAuthenticatePk method, which authenticates with the SSH server
//  using public-key authentication after an SSH tunnel has been opened.  The 1st argument is
//  the SSH account name and the 2nd is the SSH private key.

mailman := TChilkatMailMan.Create(Self);

//  Configure the POP3 server connection.  These connections will travel through the tunnel.
mailman.MailHost := 'pop.example.com';
mailman.MailPort := 995;
mailman.PopSsl := 1;
mailman.PopUsername := 'user@example.com';
mailman.PopPassword := 'myPassword';

//  Open the SSH tunnel first.
success := mailman.SshOpenTunnel('ssh.example.com',22);
if (success = 0) then
  begin
    Memo1.Lines.Add(mailman.LastErrorText);
    Exit;
  end;

//  Load the SSH private key from an OpenSSH-format key file.
sshKey := TChilkatSshKey.Create(Self);
keyText := sshKey.LoadText('qa_data/ssh/id_rsa');
if (sshKey.LastMethodSuccess = 0) then
  begin
    Memo1.Lines.Add(sshKey.LastErrorText);
    Exit;
  end;
success := sshKey.FromOpenSshPrivateKey(keyText);
if (success = 0) then
  begin
    Memo1.Lines.Add(sshKey.LastErrorText);
    Exit;
  end;

//  Authenticate with the SSH server using the private key.
success := mailman.SshAuthenticatePk('sshUser',sshKey.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(mailman.LastErrorText);
    Exit;
  end;

//  POP3 operations now travel through the SSH tunnel.
count := mailman.GetMailboxCount();
if (count < 0) then
  begin
    Memo1.Lines.Add('Failed to get the mailbox count.');
  end
else
  begin
    Memo1.Lines.Add('Mailbox count: ' + IntToStr(count));
  end;

success := mailman.SshCloseTunnel();
if (success = 0) then
  begin
    Memo1.Lines.Add(mailman.LastErrorText);
    Exit;
  end;

//  Note: The path "qa_data/ssh/id_rsa" is a relative local filesystem path,
//  relative to the current working directory of the running application.