Swift
Swift
SSH Keyboard-Interactive Authentication
See more SSH Examples
Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.
Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.
Chilkat Swift Downloads
func chilkatTest() {
var success: Bool = false
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Demonstrates keyboard-interactive authentication with an SSH server. The server sends one or
// more prompts as XML, and the application answers each with ContinueKeyboardAuth.
let ssh = CkoSsh()!
ssh.connectTimeoutMs = 5000
ssh.readTimeoutMs = 15000
var hostname: String? = "ssh.example.com"
var port: Int = 22
success = ssh.connect(hostname: hostname, port: port)
if success == false {
print("\(ssh.lastErrorText!)")
return
}
// Begin keyboard-interactive authentication. The returned XML describes the server's prompts.
var xmlResponse: String? = ssh.startKeyboardAuth(login: "mySshLogin")
if ssh.lastMethodSuccess == false {
print("\(ssh.lastErrorText!)")
return
}
// If the server sent a user authentication banner, an application may display it before
// prompting.
print("UserAuthBanner: \(ssh.userAuthBanner!)")
let xml = CkoXml()!
success = xml.load(xmlData: xmlResponse)
if success == false {
print("\(xml.lastErrorText!)")
return
}
// Authentication is complete when the XML contains either a "success" or an "error" node.
if xml.hasChild(withTag: "success") {
print("No password required, already authenticated.")
return
}
if xml.hasChild(withTag: "error") {
print("Authentication failed.")
return
}
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
var password: String? = "mySshPassword"
// Answer the prompt. Typically one call is enough, but a server may issue several rounds of
// prompts, so a robust client loops until it sees "success" or "error".
xmlResponse = ssh.continueKeyboardAuth(response: password)
if ssh.lastMethodSuccess == false {
print("\(ssh.lastErrorText!)")
return
}
success = xml.load(xmlData: xmlResponse)
if success == false {
print("\(xml.lastErrorText!)")
return
}
if xml.hasChild(withTag: "success") {
print("SSH keyboard-interactive authentication successful.")
return
}
if xml.hasChild(withTag: "error") {
print("Authentication failed.")
}
}