Sample code for 30+ languages & platforms
Pascal (Lazarus/Delphi)

SSH Set Allowed Algorithms

See more SSH Examples

Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories, in order of preference, and is applied before connecting.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities such as the Terrapin attack.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm, or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old device. Otherwise the safer default is to let the library's ordering evolve as cryptographic guidance changes.

Chilkat Pascal (Lazarus/Delphi) Downloads

Pascal (Lazarus/Delphi)
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.Ssh,
  Chilkat.JsonObject;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  ssh: TSsh;
  json: TJsonObject;
  allowed_kex: string;
  allowed_hostKey: string;
  allowed_cipher: string;
  allowed_mac: string;
  port: Integer;

begin
  success := False;

  //  This example requires the Chilkat API to have been previously unlocked.
  //  See Global Unlock Sample for sample code.

  //  Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation.
  //  
  //  -------------------------------------------------------------------------------------------
  //  Note: You typically should NOT explicitly set allowed algorithms.
  //  By default, Chilkat orders algorithms according to best practices and accounts for known
  //  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms makes an application
  //  brittle over time: if a server later changes its allowed algorithms, or if you connect to a
  //  different server, the client and server may fail to agree on a mutually supported set.
  //  -------------------------------------------------------------------------------------------

  ssh := TSsh.Create;

  json := TJsonObject.Create;

  //  Algorithms supported by Chilkat, by category:
  //  
  //  Key-exchange:  curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256,
  //    ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group14-sha256,
  //    diffie-hellman-group16-sha512, diffie-hellman-group18-sha512,
  //    diffie-hellman-group-exchange-sha256, diffie-hellman-group1-sha1,
  //    diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1
  //  
  //  Host key:  ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521,
  //    rsa-sha2-256, rsa-sha2-512, ssh-rsa, ssh-dss
  //  
  //  Cipher:  chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes192-ctr, aes128-cbc,
  //    aes256-cbc, aes192-cbc, aes128-gcm@openssh.com, aes256-gcm@openssh.com, twofish256-cbc,
  //    twofish128-cbc, blowfish-cbc
  //  
  //  MAC:  hmac-sha2-256, hmac-sha2-512, hmac-sha2-256-etm@openssh.com,
  //    hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, hmac-sha1, hmac-ripemd160,
  //    hmac-sha1-96, hmac-md5

  //  List the allowed algorithms for each category, in order of preference.
  allowed_kex := 'curve25519-sha256@libssh.org,ecdh-sha2-nistp256';
  allowed_hostKey := 'ssh-ed25519,ecdsa-sha2-nistp256';
  allowed_cipher := 'chacha20-poly1305@openssh.com,aes256-ctr';
  allowed_mac := 'hmac-sha2-256,hmac-sha2-512';

  json.UpdateString('kex',allowed_kex);
  json.UpdateString('hostKey',allowed_hostKey);
  json.UpdateString('cipher',allowed_cipher);
  json.UpdateString('mac',allowed_mac);

  //  Apply the allow-list.  This must be done before connecting.
  success := ssh.SetAllowedAlgorithms(json);
  if (success = False) then
    begin
      WriteLn(ssh.LastErrorText);
      Exit;
    end;

  port := 22;
  success := ssh.Connect('ssh.example.com',port);
  if (success = False) then
    begin
      WriteLn(ssh.LastErrorText);
      Exit;
    end;

  WriteLn('Connected.');

  ssh.Disconnect();


  ssh.Free;
  json.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.