Sample code for 30+ languages & platforms
PureBasic

SFTP Set Allowed SSH Algorithms

See more SFTP Examples

Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkJsonObject.pb"
IncludeFile "CkSFtp.pb"

Procedure ChilkatExample()

    success.i = 0

    ;  Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
    ;  algorithms permitted for the connection.  The only argument is a JsonObject.  It must be
    ;  called before Connect.
    ;  
    ;  -------------------------------------------------------------------------------------------
    ;  Note: You typically should NOT explicitly set allowed algorithms.
    ;  By default, Chilkat orders algorithms according to best practices and accounts for known
    ;  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms can make an
    ;  application brittle over time: if a server later changes its allowed algorithms, or if you
    ;  connect to a different server, the client and server may fail to agree on a mutually
    ;  supported set.
    ;  -------------------------------------------------------------------------------------------

    sftp.i = CkSFtp::ckCreate()
    If sftp.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    json.i = CkJsonObject::ckCreate()
    If json.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ;  The algorithms supported by Chilkat, by category:
    ;  
    ;  Key-exchange:
    ;    curve25519-sha256
    ;    curve25519-sha256@libssh.org
    ;    ecdh-sha2-nistp256
    ;    ecdh-sha2-nistp384
    ;    ecdh-sha2-nistp521
    ;    diffie-hellman-group14-sha256
    ;    diffie-hellman-group16-sha512
    ;    diffie-hellman-group18-sha512
    ;    diffie-hellman-group-exchange-sha256
    ;    diffie-hellman-group1-sha1
    ;    diffie-hellman-group14-sha1
    ;    diffie-hellman-group-exchange-sha1
    ;  
    ;  Host key:
    ;    ssh-ed25519
    ;    ecdsa-sha2-nistp256
    ;    ecdsa-sha2-nistp384
    ;    ecdsa-sha2-nistp521
    ;    rsa-sha2-256
    ;    rsa-sha2-512
    ;    ssh-rsa
    ;    ssh-dss
    ;  
    ;  Cipher (encryption):
    ;    chacha20-poly1305@openssh.com
    ;    aes128-ctr
    ;    aes256-ctr
    ;    aes192-ctr
    ;    aes128-cbc
    ;    aes256-cbc
    ;    aes192-cbc
    ;    aes128-gcm@openssh.com
    ;    aes256-gcm@openssh.com
    ;    twofish256-cbc
    ;    twofish128-cbc
    ;    blowfish-cbc
    ;  
    ;  MAC (hash):
    ;    hmac-sha2-256
    ;    hmac-sha2-512
    ;    hmac-sha2-256-etm@openssh.com
    ;    hmac-sha2-512-etm@openssh.com
    ;    hmac-sha1-etm@openssh.com
    ;    hmac-sha1
    ;    hmac-ripemd160
    ;    hmac-sha1-96
    ;    hmac-md5

    ;  List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
    ;  order of preference.
    allowed_kex.s = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
    allowed_hostKey.s = "ssh-ed25519,ecdsa-sha2-nistp256"
    allowed_cipher.s = "chacha20-poly1305@openssh.com,aes256-ctr"
    allowed_mac.s = "hmac-sha2-256,hmac-sha2-512"

    CkJsonObject::ckUpdateString(json,"kex",allowed_kex)
    CkJsonObject::ckUpdateString(json,"hostKey",allowed_hostKey)
    CkJsonObject::ckUpdateString(json,"cipher",allowed_cipher)
    CkJsonObject::ckUpdateString(json,"mac",allowed_mac)

    ;  Apply the allow-list before connecting.
    success = CkSFtp::ckSetAllowedAlgorithms(sftp,json)
    If success = 0
        Debug CkSFtp::ckLastErrorText(sftp)
        CkSFtp::ckDispose(sftp)
        CkJsonObject::ckDispose(json)
        ProcedureReturn
    EndIf

    port.i = 22
    success = CkSFtp::ckConnect(sftp,"sftp.example.com",port)
    If success = 0
        Debug CkSFtp::ckLastErrorText(sftp)
        CkSFtp::ckDispose(sftp)
        CkJsonObject::ckDispose(json)
        ProcedureReturn
    EndIf

    Debug "Connected."

    CkSFtp::ckDisconnect(sftp)


    CkSFtp::ckDispose(sftp)
    CkJsonObject::ckDispose(json)


    ProcedureReturn
EndProcedure