Sample code for 30+ languages & platforms
Lazarus Pascal

Continue SSH Tunnel Keyboard-Interactive Authentication

See more SSH Tunnel Examples

Demonstrates the Chilkat SshTunnel.ContinueKeyboardAuth method, which submits a response to a keyboard-interactive prompt. The only argument is the response text; for a request with multiple prompts, an XML response is supplied instead. It returns XML indicating the next prompt or the final result.

Background: This is the second half of the exchange started by StartKeyboardAuth. A server may issue several rounds of prompts, so a robust client loops: submit answers, read the returned XML, and continue until it sees success or failure. On success, BeginAccepting still must be called before the tunnel forwards traffic.

Chilkat Lazarus Pascal Downloads

Lazarus Pascal
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.SshTunnel;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  tunnel: TSshTunnel;
  sshPort: Integer;
  infoRequestXml: string;
  password: string;
  result: string;
  waitForThreadExit: Boolean;

begin
  success := False;

  //  Demonstrates the SshTunnel.ContinueKeyboardAuth method, which submits a response to a
  //  keyboard-interactive prompt.  The only argument is the response.  For multiple prompts, an XML
  //  response is supplied instead.

  tunnel := TSshTunnel.Create;

  //  The tunnel forwards accepted local connections to this destination through the SSH server.
  tunnel.DestHostname := 'db.internal.example.com';
  tunnel.DestPort := 5432;

  //  Connect to the SSH server.  This performs the TCP/proxy connection and SSH handshake, but
  //  does not authenticate yet.
  sshPort := 22;
  success := tunnel.Connect('ssh.example.com',sshPort);
  if (success = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;

  //  Begin keyboard-interactive authentication to receive the server's prompt(s).
  infoRequestXml := tunnel.StartKeyboardAuth('mySshLogin');
  if (tunnel.LastMethodSuccess = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;

  //  Normally you would not hard-code the password in source.  You should instead obtain it
  //  from an interactive prompt, environment variable, or a secrets vault.
  password := 'mySshPassword';

  //  Submit the response (typically the password).  The returned XML indicates the next prompt or
  //  the final result.
  result := tunnel.ContinueKeyboardAuth(password);
  if (tunnel.LastMethodSuccess = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;
  WriteLn(result);

  waitForThreadExit := True;
  success := tunnel.CloseTunnel(waitForThreadExit);
  if (success = False) then
    begin
      WriteLn(tunnel.LastErrorText);
      Exit;
    end;


  tunnel.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.