Sample code for 30+ languages & platforms
SQL Server

SFTP Set Allowed SSH Algorithms

See more SFTP Examples

Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @sTmp0 nvarchar(4000)
    DECLARE @success int
    SELECT @success = 0

    --  Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
    --  algorithms permitted for the connection.  The only argument is a JsonObject.  It must be
    --  called before Connect.
    --  
    --  -------------------------------------------------------------------------------------------
    --  Note: You typically should NOT explicitly set allowed algorithms.
    --  By default, Chilkat orders algorithms according to best practices and accounts for known
    --  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms can make an
    --  application brittle over time: if a server later changes its allowed algorithms, or if you
    --  connect to a different server, the client and server may fail to agree on a mutually
    --  supported set.
    --  -------------------------------------------------------------------------------------------

    DECLARE @sftp int
    EXEC @hr = sp_OACreate 'Chilkat.SFtp', @sftp OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    DECLARE @json int
    EXEC @hr = sp_OACreate 'Chilkat.JsonObject', @json OUT

    --  The algorithms supported by Chilkat, by category:
    --  
    --  Key-exchange:
    --    curve25519-sha256
    --    curve25519-sha256@libssh.org
    --    ecdh-sha2-nistp256
    --    ecdh-sha2-nistp384
    --    ecdh-sha2-nistp521
    --    diffie-hellman-group14-sha256
    --    diffie-hellman-group16-sha512
    --    diffie-hellman-group18-sha512
    --    diffie-hellman-group-exchange-sha256
    --    diffie-hellman-group1-sha1
    --    diffie-hellman-group14-sha1
    --    diffie-hellman-group-exchange-sha1
    --  
    --  Host key:
    --    ssh-ed25519
    --    ecdsa-sha2-nistp256
    --    ecdsa-sha2-nistp384
    --    ecdsa-sha2-nistp521
    --    rsa-sha2-256
    --    rsa-sha2-512
    --    ssh-rsa
    --    ssh-dss
    --  
    --  Cipher (encryption):
    --    chacha20-poly1305@openssh.com
    --    aes128-ctr
    --    aes256-ctr
    --    aes192-ctr
    --    aes128-cbc
    --    aes256-cbc
    --    aes192-cbc
    --    aes128-gcm@openssh.com
    --    aes256-gcm@openssh.com
    --    twofish256-cbc
    --    twofish128-cbc
    --    blowfish-cbc
    --  
    --  MAC (hash):
    --    hmac-sha2-256
    --    hmac-sha2-512
    --    hmac-sha2-256-etm@openssh.com
    --    hmac-sha2-512-etm@openssh.com
    --    hmac-sha1-etm@openssh.com
    --    hmac-sha1
    --    hmac-ripemd160
    --    hmac-sha1-96
    --    hmac-md5

    --  List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
    --  order of preference.
    DECLARE @allowed_kex nvarchar(4000)
    SELECT @allowed_kex = 'curve25519-sha256@libssh.org,ecdh-sha2-nistp256'
    DECLARE @allowed_hostKey nvarchar(4000)
    SELECT @allowed_hostKey = 'ssh-ed25519,ecdsa-sha2-nistp256'
    DECLARE @allowed_cipher nvarchar(4000)
    SELECT @allowed_cipher = 'chacha20-poly1305@openssh.com,aes256-ctr'
    DECLARE @allowed_mac nvarchar(4000)
    SELECT @allowed_mac = 'hmac-sha2-256,hmac-sha2-512'

    EXEC sp_OAMethod @json, 'UpdateString', @success OUT, 'kex', @allowed_kex
    EXEC sp_OAMethod @json, 'UpdateString', @success OUT, 'hostKey', @allowed_hostKey
    EXEC sp_OAMethod @json, 'UpdateString', @success OUT, 'cipher', @allowed_cipher
    EXEC sp_OAMethod @json, 'UpdateString', @success OUT, 'mac', @allowed_mac

    --  Apply the allow-list before connecting.
    EXEC sp_OAMethod @sftp, 'SetAllowedAlgorithms', @success OUT, @json
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @sftp, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @sftp
        EXEC @hr = sp_OADestroy @json
        RETURN
      END

    DECLARE @port int
    SELECT @port = 22
    EXEC sp_OAMethod @sftp, 'Connect', @success OUT, 'sftp.example.com', @port
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @sftp, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @sftp
        EXEC @hr = sp_OADestroy @json
        RETURN
      END

    PRINT 'Connected.'

    EXEC sp_OAMethod @sftp, 'Disconnect', NULL

    EXEC @hr = sp_OADestroy @sftp
    EXEC @hr = sp_OADestroy @json


END
GO