Sample code for 30+ languages & platforms
SQL Server

SSH Tunnel Authenticate with a SecureString Password

See more SSH Tunnel Examples

Demonstrates the Chilkat SshTunnel.AuthenticateSecPw method, which authenticates using SecureString login and password objects. The first argument is the login and the second is the password.

Background: Because a tunnel process is long-lived and holds its SSH credentials for its entire lifetime, protecting them in memory is worthwhile. A SecureString keeps the value encrypted under a randomly generated session key. Populate it from a value obtained at runtime rather than a hard-coded literal.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @sTmp0 nvarchar(4000)
    DECLARE @success int
    SELECT @success = 0

    --  Demonstrates the SshTunnel.AuthenticateSecPw method, which authenticates using SecureString
    --  login and password objects.  The 1st argument is the login and the 2nd is the password.

    DECLARE @tunnel int
    EXEC @hr = sp_OACreate 'Chilkat.SshTunnel', @tunnel OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    --  The tunnel forwards accepted local connections to this destination through the SSH server.
    EXEC sp_OASetProperty @tunnel, 'DestHostname', 'db.internal.example.com'
    EXEC sp_OASetProperty @tunnel, 'DestPort', 5432

    --  Connect to the SSH server.  This performs the TCP/proxy connection and SSH handshake, but
    --  does not authenticate yet.
    DECLARE @sshPort int
    SELECT @sshPort = 22
    EXEC sp_OAMethod @tunnel, 'Connect', @success OUT, 'ssh.example.com', @sshPort
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @tunnel
        RETURN
      END

    --  Normally you would not hard-code the password in source.  You should instead obtain it
    --  from an interactive prompt, environment variable, or a secrets vault.
    DECLARE @password nvarchar(4000)
    SELECT @password = 'mySshPassword'

    --  Place the login and password into SecureString objects.
    DECLARE @secureLogin int
    EXEC @hr = sp_OACreate 'Chilkat.SecureString', @secureLogin OUT

    EXEC sp_OAMethod @secureLogin, 'Append', @success OUT, 'mySshLogin'
    DECLARE @securePassword int
    EXEC @hr = sp_OACreate 'Chilkat.SecureString', @securePassword OUT

    EXEC sp_OAMethod @securePassword, 'Append', @success OUT, @password

    EXEC sp_OAMethod @tunnel, 'AuthenticateSecPw', @success OUT, @secureLogin, @securePassword
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @tunnel
        EXEC @hr = sp_OADestroy @secureLogin
        EXEC @hr = sp_OADestroy @securePassword
        RETURN
      END

    PRINT 'Authenticated with secure strings.'

    --  After authenticating, call BeginAccepting to start listening for local connections to forward.

    DECLARE @waitForThreadExit int
    SELECT @waitForThreadExit = 1
    EXEC sp_OAMethod @tunnel, 'CloseTunnel', @success OUT, @waitForThreadExit
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @tunnel, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @tunnel
        EXEC @hr = sp_OADestroy @secureLogin
        EXEC @hr = sp_OADestroy @securePassword
        RETURN
      END

    EXEC @hr = sp_OADestroy @tunnel
    EXEC @hr = sp_OADestroy @secureLogin
    EXEC @hr = sp_OADestroy @securePassword


END
GO