Sample code for 30+ languages & platforms
PureBasic

SSH Set Allowed Algorithms

See more SSH Examples

Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories, in order of preference, and is applied before connecting.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities such as the Terrapin attack.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm, or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old device. Otherwise the safer default is to let the library's ordering evolve as cryptographic guidance changes.

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkSsh.pb"
IncludeFile "CkJsonObject.pb"

Procedure ChilkatExample()

    success.i = 0

    ;  This example requires the Chilkat API to have been previously unlocked.
    ;  See Global Unlock Sample for sample code.

    ;  Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation.
    ;  
    ;  -------------------------------------------------------------------------------------------
    ;  Note: You typically should NOT explicitly set allowed algorithms.
    ;  By default, Chilkat orders algorithms according to best practices and accounts for known
    ;  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms makes an application
    ;  brittle over time: if a server later changes its allowed algorithms, or if you connect to a
    ;  different server, the client and server may fail to agree on a mutually supported set.
    ;  -------------------------------------------------------------------------------------------

    ssh.i = CkSsh::ckCreate()
    If ssh.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    json.i = CkJsonObject::ckCreate()
    If json.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ;  Algorithms supported by Chilkat, by category:
    ;  
    ;  Key-exchange:  curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256,
    ;    ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group14-sha256,
    ;    diffie-hellman-group16-sha512, diffie-hellman-group18-sha512,
    ;    diffie-hellman-group-exchange-sha256, diffie-hellman-group1-sha1,
    ;    diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1
    ;  
    ;  Host key:  ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521,
    ;    rsa-sha2-256, rsa-sha2-512, ssh-rsa, ssh-dss
    ;  
    ;  Cipher:  chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes192-ctr, aes128-cbc,
    ;    aes256-cbc, aes192-cbc, aes128-gcm@openssh.com, aes256-gcm@openssh.com, twofish256-cbc,
    ;    twofish128-cbc, blowfish-cbc
    ;  
    ;  MAC:  hmac-sha2-256, hmac-sha2-512, hmac-sha2-256-etm@openssh.com,
    ;    hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, hmac-sha1, hmac-ripemd160,
    ;    hmac-sha1-96, hmac-md5

    ;  List the allowed algorithms for each category, in order of preference.
    allowed_kex.s = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
    allowed_hostKey.s = "ssh-ed25519,ecdsa-sha2-nistp256"
    allowed_cipher.s = "chacha20-poly1305@openssh.com,aes256-ctr"
    allowed_mac.s = "hmac-sha2-256,hmac-sha2-512"

    CkJsonObject::ckUpdateString(json,"kex",allowed_kex)
    CkJsonObject::ckUpdateString(json,"hostKey",allowed_hostKey)
    CkJsonObject::ckUpdateString(json,"cipher",allowed_cipher)
    CkJsonObject::ckUpdateString(json,"mac",allowed_mac)

    ;  Apply the allow-list.  This must be done before connecting.
    success = CkSsh::ckSetAllowedAlgorithms(ssh,json)
    If success = 0
        Debug CkSsh::ckLastErrorText(ssh)
        CkSsh::ckDispose(ssh)
        CkJsonObject::ckDispose(json)
        ProcedureReturn
    EndIf

    port.i = 22
    success = CkSsh::ckConnect(ssh,"ssh.example.com",port)
    If success = 0
        Debug CkSsh::ckLastErrorText(ssh)
        CkSsh::ckDispose(ssh)
        CkJsonObject::ckDispose(json)
        ProcedureReturn
    EndIf

    Debug "Connected."

    CkSsh::ckDisconnect(ssh)


    CkSsh::ckDispose(ssh)
    CkJsonObject::ckDispose(json)


    ProcedureReturn
EndProcedure