PowerBuilder
PowerBuilder
SSH Tunnel Authenticate with a SecureString Password and Private Key
See more SSH Tunnel Examples
Demonstrates the Chilkat SshTunnel.AuthenticateSecPwPk method, which authenticates using SecureString login and password objects together with a private key. The third argument is the SshKey private key.
Note: The private-key path is relative to the application's current working directory. Absolute paths may also be used. Supply the path to your own key file.
Background: This is the
SecureString form of two-factor tunnel authentication: the password is held encrypted in memory and combined with a private key for servers that require both. It is the most protective option when a deployment mandates two-factor SSH and you also want to minimize plaintext credential exposure in a long-running process.Chilkat PowerBuilder Downloads
integer li_rc
integer li_Success
oleobject loo_Tunnel
integer li_SshPort
string ls_Password
oleobject loo_PrivKey
string ls_KeyText
oleobject loo_SecureLogin
oleobject loo_SecurePassword
integer li_WaitForThreadExit
li_Success = 0
// Demonstrates the SshTunnel.AuthenticateSecPwPk method, which authenticates using SecureString
// login and password objects together with a private key. The 1st argument is the username, the
// 2nd is the password, and the 3rd is an SshKey private key.
loo_Tunnel = create oleobject
li_rc = loo_Tunnel.ConnectToNewObject("Chilkat.SshTunnel")
if li_rc < 0 then
destroy loo_Tunnel
MessageBox("Error","Connecting to COM object failed")
return
end if
// The tunnel forwards accepted local connections to this destination through the SSH server.
loo_Tunnel.DestHostname = "db.internal.example.com"
loo_Tunnel.DestPort = 5432
// Connect to the SSH server. This performs the TCP/proxy connection and SSH handshake, but
// does not authenticate yet.
li_SshPort = 22
li_Success = loo_Tunnel.Connect("ssh.example.com",li_SshPort)
if li_Success = 0 then
Write-Debug loo_Tunnel.LastErrorText
destroy loo_Tunnel
return
end if
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
ls_Password = "mySshPassword"
// Load the SSH private key. LoadText reads the file's text, which is then imported.
loo_PrivKey = create oleobject
li_rc = loo_PrivKey.ConnectToNewObject("Chilkat.SshKey")
ls_KeyText = loo_PrivKey.LoadText("qa_data/id_rsa")
if loo_PrivKey.LastMethodSuccess = 0 then
Write-Debug loo_PrivKey.LastErrorText
destroy loo_Tunnel
destroy loo_PrivKey
return
end if
li_Success = loo_PrivKey.FromOpenSshPrivateKey(ls_KeyText)
if li_Success = 0 then
Write-Debug loo_PrivKey.LastErrorText
destroy loo_Tunnel
destroy loo_PrivKey
return
end if
// Place the login and password into SecureString objects.
loo_SecureLogin = create oleobject
li_rc = loo_SecureLogin.ConnectToNewObject("Chilkat.SecureString")
loo_SecureLogin.Append("mySshLogin")
loo_SecurePassword = create oleobject
li_rc = loo_SecurePassword.ConnectToNewObject("Chilkat.SecureString")
loo_SecurePassword.Append(ls_Password)
li_Success = loo_Tunnel.AuthenticateSecPwPk(loo_SecureLogin,loo_SecurePassword,loo_PrivKey)
if li_Success = 0 then
Write-Debug loo_Tunnel.LastErrorText
destroy loo_Tunnel
destroy loo_PrivKey
destroy loo_SecureLogin
destroy loo_SecurePassword
return
end if
Write-Debug "Authenticated."
// After authenticating, call BeginAccepting to start listening for local connections to forward.
li_WaitForThreadExit = 1
li_Success = loo_Tunnel.CloseTunnel(li_WaitForThreadExit)
if li_Success = 0 then
Write-Debug loo_Tunnel.LastErrorText
destroy loo_Tunnel
destroy loo_PrivKey
destroy loo_SecureLogin
destroy loo_SecurePassword
return
end if
destroy loo_Tunnel
destroy loo_PrivKey
destroy loo_SecureLogin
destroy loo_SecurePassword