SQL Server
SQL Server
SSH Tunnel Authenticate with a SecureString Password
See more SSH Tunnel Examples
Demonstrates the Chilkat SshTunnel.AuthenticateSecPw method, which authenticates using SecureString login and password objects. The first argument is the login and the second is the password.
Background: Because a tunnel process is long-lived and holds its SSH credentials for its entire lifetime, protecting them in memory is worthwhile. A
SecureString keeps the value encrypted under a randomly generated session key. Populate it from a value obtained at runtime rather than a hard-coded literal.Chilkat SQL Server Downloads
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
DECLARE @hr int
DECLARE @sTmp0 nvarchar(4000)
DECLARE @success int
SELECT @success = 0
-- Demonstrates the SshTunnel.AuthenticateSecPw method, which authenticates using SecureString
-- login and password objects. The 1st argument is the login and the 2nd is the password.
DECLARE @tunnel int
EXEC @hr = sp_OACreate 'Chilkat.SshTunnel', @tunnel OUT
IF @hr <> 0
BEGIN
PRINT 'Failed to create ActiveX component'
RETURN
END
-- The tunnel forwards accepted local connections to this destination through the SSH server.
EXEC sp_OASetProperty @tunnel, 'DestHostname', 'db.internal.example.com'
EXEC sp_OASetProperty @tunnel, 'DestPort', 5432
-- Connect to the SSH server. This performs the TCP/proxy connection and SSH handshake, but
-- does not authenticate yet.
DECLARE @sshPort int
SELECT @sshPort = 22
EXEC sp_OAMethod @tunnel, 'Connect', @success OUT, 'ssh.example.com', @sshPort
IF @success = 0
BEGIN
EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
PRINT @sTmp0
EXEC @hr = sp_OADestroy @tunnel
RETURN
END
-- Normally you would not hard-code the password in source. You should instead obtain it
-- from an interactive prompt, environment variable, or a secrets vault.
DECLARE @password nvarchar(4000)
SELECT @password = 'mySshPassword'
-- Place the login and password into SecureString objects.
DECLARE @secureLogin int
EXEC @hr = sp_OACreate 'Chilkat.SecureString', @secureLogin OUT
EXEC sp_OAMethod @secureLogin, 'Append', @success OUT, 'mySshLogin'
DECLARE @securePassword int
EXEC @hr = sp_OACreate 'Chilkat.SecureString', @securePassword OUT
EXEC sp_OAMethod @securePassword, 'Append', @success OUT, @password
EXEC sp_OAMethod @tunnel, 'AuthenticateSecPw', @success OUT, @secureLogin, @securePassword
IF @success = 0
BEGIN
EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
PRINT @sTmp0
EXEC @hr = sp_OADestroy @tunnel
EXEC @hr = sp_OADestroy @secureLogin
EXEC @hr = sp_OADestroy @securePassword
RETURN
END
PRINT 'Authenticated with secure strings.'
-- After authenticating, call BeginAccepting to start listening for local connections to forward.
DECLARE @waitForThreadExit int
SELECT @waitForThreadExit = 1
EXEC sp_OAMethod @tunnel, 'CloseTunnel', @success OUT, @waitForThreadExit
IF @success = 0
BEGIN
EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
PRINT @sTmp0
EXEC @hr = sp_OADestroy @tunnel
EXEC @hr = sp_OADestroy @secureLogin
EXEC @hr = sp_OADestroy @securePassword
RETURN
END
EXEC @hr = sp_OADestroy @tunnel
EXEC @hr = sp_OADestroy @secureLogin
EXEC @hr = sp_OADestroy @securePassword
END
GO