Sample code for 30+ languages & platforms
Pascal (Lazarus/Delphi)

SSH Tunnel Authenticate with a Private Key

See more SSH Tunnel Examples

Demonstrates the Chilkat SshTunnel.AuthenticatePk method, which authenticates the SSH connection using public-key authentication. The first argument is the username and the second is an SshKey private key. The matching public key must already be installed for the account on the SSH server.

Note: The private-key path is relative to the application's current working directory. Absolute paths may also be used. Supply the path to your own key file.

Background: Public-key authentication suits tunnels especially well because they typically run unattended for long periods: the private key stays on the client, the server trusts the corresponding public key, and no reusable password crosses the wire. The SshKey object imports several formats; for an encrypted key, set its Password before importing.

Chilkat Pascal (Lazarus/Delphi) Downloads

Pascal (Lazarus/Delphi)
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.SshTunnel,
  Chilkat.SshKey;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  tunnel: TSshTunnel;
  sshPort: Integer;
  privKey: TSshKey;
  keyText: string;
  waitForThreadExit: Boolean;

begin
  success := False;

  //  Demonstrates the SshTunnel.AuthenticatePk method, which authenticates the SSH connection using
  //  public-key authentication.  The 1st argument is the username and the 2nd is an SshKey private
  //  key.  The matching public key must already be installed for the account on the SSH server.

  tunnel := TSshTunnel.Create;

  //  The tunnel forwards accepted local connections to this destination through the SSH server.
  tunnel.DestHostname := 'db.internal.example.com';
  tunnel.DestPort := 5432;

  //  Connect to the SSH server.  This performs the TCP/proxy connection and SSH handshake, but
  //  does not authenticate yet.
  sshPort := 22;
  success := tunnel.Connect('ssh.example.com',sshPort);
  if (success = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;

  //  Load the SSH private key.  LoadText reads the file's text, which is then imported.
  privKey := TSshKey.Create;
  keyText := privKey.LoadText('qa_data/id_rsa');
  if (privKey.LastMethodSuccess = False) then
    begin
      WriteLn(privKey.LastErrorText);
      Exit;
    end;
  success := privKey.FromOpenSshPrivateKey(keyText);
  if (success = False) then
    begin
      WriteLn(privKey.LastErrorText);
      Exit;
    end;

  success := tunnel.AuthenticatePk('mySshLogin',privKey);
  if (success = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;
  WriteLn('Authenticated with a private key.');

  //  After authenticating, call BeginAccepting to start listening for local connections to forward.

  waitForThreadExit := True;
  success := tunnel.CloseTunnel(waitForThreadExit);
  if (success = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;


  tunnel.Free;
  privKey.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.