Sample code for 30+ languages & platforms
Pascal (Lazarus/Delphi)

Get the SFTP Server Host Key Fingerprint

See more SFTP Examples

Demonstrates the Chilkat SFtp.GetHostKeyFP method, which returns the connected server's host-key fingerprint. The first argument is the hash algorithm (for example SHA256 or MD5), the second controls whether the key type is included, and the third controls whether the hash name is included.

Background: The host-key fingerprint identifies the server. Comparing it against a known-good value is how a client implements host-key pinning — detecting a man-in-the-middle attempt or a changed server key before trusting the connection with credentials or files. SHA256 is the modern default; MD5 fingerprints still appear in older tooling but are weaker.

Chilkat Pascal (Lazarus/Delphi) Downloads

Pascal (Lazarus/Delphi)
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.SFtp;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  sftp: TSFtp;
  port: Integer;
  includeKeyType: Boolean;
  includeHashName: Boolean;
  fingerprint: string;

begin
  success := False;

  //  Demonstrates the SFtp.GetHostKeyFP method, which returns the server's host-key fingerprint.
  //  The 1st argument is the hash algorithm, the 2nd controls whether the key type is included, and
  //  the 3rd controls whether the hash name is included.

  sftp := TSFtp.Create;

  //  Step 1: Connect the SSH transport.  Port 22 is the usual port.
  port := 22;
  success := sftp.Connect('sftp.example.com',port);
  if (success = False) then
    begin
      WriteLn(sftp.LastErrorText);
      Exit;
    end;

  //  Get the SHA256 fingerprint, including the key type and hash name.
  includeKeyType := True;
  includeHashName := True;
  fingerprint := sftp.GetHostKeyFP('SHA256',includeKeyType,includeHashName);
  if (sftp.LastMethodSuccess = False) then
    begin
      WriteLn(sftp.LastErrorText);
      Exit;
    end;
  WriteLn('Host key fingerprint: ' + fingerprint);

  sftp.Disconnect();


  sftp.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.