Sample code for 30+ languages & platforms
Go

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Go Downloads

Go
    success := false

    //  This example requires the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    //  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
    //  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

    ssh := chilkat.NewSsh()

    ssh.SetConnectTimeoutMs(5000)
    ssh.SetReadTimeoutMs(15000)

    hostname := "ssh.example.com"
    port := 22
    success = ssh.Connect(hostname,port)
    if success == false {
        fmt.Println(ssh.LastErrorText())
        ssh.DisposeSsh()
        return
    }

    //  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
    xmlResponse := ssh.StartKeyboardAuth("mySshLogin")
    if ssh.LastMethodSuccess() == false {
        fmt.Println(ssh.LastErrorText())
        ssh.DisposeSsh()
        return
    }

    //  If the server sent a user authentication banner, an application may display it before
    //  prompting.
    fmt.Println("UserAuthBanner: ", ssh.UserAuthBanner())

    xml := chilkat.NewXml()
    success = xml.LoadXml(*xmlResponse)
    if success == false {
        fmt.Println(xml.LastErrorText())
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    //  Authentication is complete when the XML contains either a "success" or an "error" node.
    if xml.HasChildWithTag("success") {
        fmt.Println("No password required, already authenticated.")
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    if xml.HasChildWithTag("error") {
        fmt.Println("Authentication failed.")
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    password := "mySshPassword"

    //  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
    //  prompts, so a robust client loops until it sees "success" or "error".
    xmlResponse = ssh.ContinueKeyboardAuth(password)
    if ssh.LastMethodSuccess() == false {
        fmt.Println(ssh.LastErrorText())
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    success = xml.LoadXml(*xmlResponse)
    if success == false {
        fmt.Println(xml.LastErrorText())
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    if xml.HasChildWithTag("success") {
        fmt.Println("SSH keyboard-interactive authentication successful.")
        ssh.DisposeSsh()
        xml.DisposeXml()
        return
    }

    if xml.HasChildWithTag("error") {
        fmt.Println("Authentication failed.")
    }


    ssh.DisposeSsh()
    xml.DisposeXml()