Sample code for 30+ languages & platforms
Delphi ActiveX

SFTP Authentication using X.509 Certificates

See more SFTP Examples

Demonstrates how to authenticate with an SSH/SFTP server using an certificate's private key.

Note: See X.509v3 Certificates for SSH Authentication for more information.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Chilkat_TLB;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Integer;
sftp: TChilkatSFtp;
hostname: WideString;
port: Integer;
cert: TChilkatCert;
privKeyPem: WideString;
key: TChilkatSshKey;

begin
success := 0;

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

sftp := TChilkatSFtp.Create(Self);

hostname := 'sftp.example.com';
port := 22;
success := sftp.Connect(hostname,port);
if (success <> 1) then
  begin
    Memo1.Lines.Add(sftp.LastErrorText);
    Exit;
  end;

// Load the cert + private key from a .pfx.
// Note: Chilkat provides methods for loading certs and private keys from many sources, including smart cards and USB tokens (HSM's)
cert := TChilkatCert.Create(Self);
success := cert.LoadPfxFile('qa_data/pfx/example.pfx','pfx_password');
if (success <> 1) then
  begin
    Memo1.Lines.Add(cert.LastErrorText);
    Exit;
  end;

// Get the cert's private key (as PEM) to be used for SSH authentication.
// (The public key is installed on the server.)
privKeyPem := cert.GetPrivateKeyPem();
if (cert.LastMethodSuccess = 0) then
  begin
    Memo1.Lines.Add(cert.LastErrorText);
    Exit;
  end;

key := TChilkatSshKey.Create(Self);

// Load a private key from a PEM string:
success := key.FromOpenSshPrivateKey(privKeyPem);
if (success <> 1) then
  begin
    Memo1.Lines.Add(key.LastErrorText);
    Exit;
  end;

// Authenticate with the SSH server.
success := sftp.AuthenticatePk('myLogin',key.ControlInterface);
if (success <> 1) then
  begin
    Memo1.Lines.Add(sftp.LastErrorText);
    Exit;
  end;

Memo1.Lines.Add('Public-Key Authentication Successful!');
end;