Sample code for 30+ languages & platforms
PowerBuilder

SSH Tunnel Authenticate with a SecureString Password and Private Key

See more SSH Tunnel Examples

Demonstrates the Chilkat SshTunnel.AuthenticateSecPwPk method, which authenticates using SecureString login and password objects together with a private key. The third argument is the SshKey private key.

Note: The private-key path is relative to the application's current working directory. Absolute paths may also be used. Supply the path to your own key file.

Background: This is the SecureString form of two-factor tunnel authentication: the password is held encrypted in memory and combined with a private key for servers that require both. It is the most protective option when a deployment mandates two-factor SSH and you also want to minimize plaintext credential exposure in a long-running process.

Chilkat PowerBuilder Downloads

PowerBuilder
integer li_rc
integer li_Success
oleobject loo_Tunnel
integer li_SshPort
string ls_Password
oleobject loo_PrivKey
string ls_KeyText
oleobject loo_SecureLogin
oleobject loo_SecurePassword
integer li_WaitForThreadExit

li_Success = 0

//  Demonstrates the SshTunnel.AuthenticateSecPwPk method, which authenticates using SecureString
//  login and password objects together with a private key.  The 1st argument is the username, the
//  2nd is the password, and the 3rd is an SshKey private key.

loo_Tunnel = create oleobject
li_rc = loo_Tunnel.ConnectToNewObject("Chilkat.SshTunnel")
if li_rc < 0 then
    destroy loo_Tunnel
    MessageBox("Error","Connecting to COM object failed")
    return
end if

//  The tunnel forwards accepted local connections to this destination through the SSH server.
loo_Tunnel.DestHostname = "db.internal.example.com"
loo_Tunnel.DestPort = 5432

//  Connect to the SSH server.  This performs the TCP/proxy connection and SSH handshake, but
//  does not authenticate yet.
li_SshPort = 22
li_Success = loo_Tunnel.Connect("ssh.example.com",li_SshPort)
if li_Success = 0 then
    Write-Debug loo_Tunnel.LastErrorText
    destroy loo_Tunnel
    return
end if

//  Normally you would not hard-code the password in source.  You should instead obtain it
//  from an interactive prompt, environment variable, or a secrets vault.
ls_Password = "mySshPassword"

//  Load the SSH private key.  LoadText reads the file's text, which is then imported.
loo_PrivKey = create oleobject
li_rc = loo_PrivKey.ConnectToNewObject("Chilkat.SshKey")

ls_KeyText = loo_PrivKey.LoadText("qa_data/id_rsa")
if loo_PrivKey.LastMethodSuccess = 0 then
    Write-Debug loo_PrivKey.LastErrorText
    destroy loo_Tunnel
    destroy loo_PrivKey
    return
end if

li_Success = loo_PrivKey.FromOpenSshPrivateKey(ls_KeyText)
if li_Success = 0 then
    Write-Debug loo_PrivKey.LastErrorText
    destroy loo_Tunnel
    destroy loo_PrivKey
    return
end if

//  Place the login and password into SecureString objects.
loo_SecureLogin = create oleobject
li_rc = loo_SecureLogin.ConnectToNewObject("Chilkat.SecureString")

loo_SecureLogin.Append("mySshLogin")
loo_SecurePassword = create oleobject
li_rc = loo_SecurePassword.ConnectToNewObject("Chilkat.SecureString")

loo_SecurePassword.Append(ls_Password)

li_Success = loo_Tunnel.AuthenticateSecPwPk(loo_SecureLogin,loo_SecurePassword,loo_PrivKey)
if li_Success = 0 then
    Write-Debug loo_Tunnel.LastErrorText
    destroy loo_Tunnel
    destroy loo_PrivKey
    destroy loo_SecureLogin
    destroy loo_SecurePassword
    return
end if

Write-Debug "Authenticated."

//  After authenticating, call BeginAccepting to start listening for local connections to forward.

li_WaitForThreadExit = 1
li_Success = loo_Tunnel.CloseTunnel(li_WaitForThreadExit)
if li_Success = 0 then
    Write-Debug loo_Tunnel.LastErrorText
    destroy loo_Tunnel
    destroy loo_PrivKey
    destroy loo_SecureLogin
    destroy loo_SecurePassword
    return
end if



destroy loo_Tunnel
destroy loo_PrivKey
destroy loo_SecureLogin
destroy loo_SecurePassword