PowerShell
PowerShell
SFTP Set Allowed SSH Algorithms
See more SFTP Examples
Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.
Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.
Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.
Chilkat PowerShell Downloads
Add-Type -Path "C:\chilkat\ChilkatDotNet47-x64\ChilkatDotNet47.dll"
$success = $false
# Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
# algorithms permitted for the connection. The only argument is a JsonObject. It must be
# called before Connect.
#
# -------------------------------------------------------------------------------------------
# Note: You typically should NOT explicitly set allowed algorithms.
# By default, Chilkat orders algorithms according to best practices and accounts for known
# vulnerabilities such as the "Terrapin Attack". Hard-coding algorithms can make an
# application brittle over time: if a server later changes its allowed algorithms, or if you
# connect to a different server, the client and server may fail to agree on a mutually
# supported set.
# -------------------------------------------------------------------------------------------
$sftp = New-Object Chilkat.SFtp
$json = New-Object Chilkat.JsonObject
# The algorithms supported by Chilkat, by category:
#
# Key-exchange:
# curve25519-sha256
# curve25519-sha256@libssh.org
# ecdh-sha2-nistp256
# ecdh-sha2-nistp384
# ecdh-sha2-nistp521
# diffie-hellman-group14-sha256
# diffie-hellman-group16-sha512
# diffie-hellman-group18-sha512
# diffie-hellman-group-exchange-sha256
# diffie-hellman-group1-sha1
# diffie-hellman-group14-sha1
# diffie-hellman-group-exchange-sha1
#
# Host key:
# ssh-ed25519
# ecdsa-sha2-nistp256
# ecdsa-sha2-nistp384
# ecdsa-sha2-nistp521
# rsa-sha2-256
# rsa-sha2-512
# ssh-rsa
# ssh-dss
#
# Cipher (encryption):
# chacha20-poly1305@openssh.com
# aes128-ctr
# aes256-ctr
# aes192-ctr
# aes128-cbc
# aes256-cbc
# aes192-cbc
# aes128-gcm@openssh.com
# aes256-gcm@openssh.com
# twofish256-cbc
# twofish128-cbc
# blowfish-cbc
#
# MAC (hash):
# hmac-sha2-256
# hmac-sha2-512
# hmac-sha2-256-etm@openssh.com
# hmac-sha2-512-etm@openssh.com
# hmac-sha1-etm@openssh.com
# hmac-sha1
# hmac-ripemd160
# hmac-sha1-96
# hmac-md5
# List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
# order of preference.
$allowed_kex = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
$allowed_hostKey = "ssh-ed25519,ecdsa-sha2-nistp256"
$allowed_cipher = "chacha20-poly1305@openssh.com,aes256-ctr"
$allowed_mac = "hmac-sha2-256,hmac-sha2-512"
$json.UpdateString("kex",$allowed_kex)
$json.UpdateString("hostKey",$allowed_hostKey)
$json.UpdateString("cipher",$allowed_cipher)
$json.UpdateString("mac",$allowed_mac)
# Apply the allow-list before connecting.
$success = $sftp.SetAllowedAlgorithms($json)
if ($success -eq $false) {
$($sftp.LastErrorText)
exit
}
$port = 22
$success = $sftp.Connect("sftp.example.com",$port)
if ($success -eq $false) {
$($sftp.LastErrorText)
exit
}
$("Connected.")
$sftp.Disconnect()