Sample code for 30+ languages & platforms
Swift

SSH Tunnel Authenticate with Password and Private Key

See more SSH Tunnel Examples

Demonstrates the Chilkat SshTunnel.AuthenticatePwPk method, which authenticates with a server that requires both a password and a private key. The arguments are the username, the password, and an SshKey private key.

Note: The private-key path is relative to the application's current working directory. Absolute paths may also be used. Supply the path to your own key file.

Background: Most servers require either a password or a public key, not both — but some high-security deployments mandate two-factor SSH. This method satisfies that policy in one call, combining something you know (the password) with something you have (the key). The password should come from a secure source rather than a literal.

Chilkat Swift Downloads

Swift

func chilkatTest() {
    var success: Bool = false

    //  Demonstrates the SshTunnel.AuthenticatePwPk method, which authenticates with an SSH server that
    //  requires BOTH a password and a private key.  The 1st argument is the username, the 2nd is the
    //  password, and the 3rd is an SshKey private key.

    let tunnel = CkoSshTunnel()!

    //  The tunnel forwards accepted local connections to this destination through the SSH server.
    tunnel.destHostname = "db.internal.example.com"
    tunnel.destPort = 5432

    //  Connect to the SSH server.  This performs the TCP/proxy connection and SSH handshake, but
    //  does not authenticate yet.
    var sshPort: Int = 22
    success = tunnel.connect(hostname: "ssh.example.com", port: sshPort)
    if success == false {
        print("\(tunnel.lastErrorText!)")
        return
    }

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    var password: String? = "mySshPassword"

    //  Load the SSH private key.  LoadText reads the file's text, which is then imported.
    let privKey = CkoSshKey()!
    var keyText: String? = privKey.loadText(path: "qa_data/id_rsa")
    if privKey.lastMethodSuccess == false {
        print("\(privKey.lastErrorText!)")
        return
    }

    success = privKey.fromOpenSshPrivateKey(keyStr: keyText)
    if success == false {
        print("\(privKey.lastErrorText!)")
        return
    }

    success = tunnel.authenticatePwPk(username: "mySshLogin", password: password, privateKey: privKey)
    if success == false {
        print("\(tunnel.lastErrorText!)")
        return
    }

    print("Authenticated with a password and a private key.")

    //  After authenticating, call BeginAccepting to start listening for local connections to forward.

    var waitForThreadExit: Bool = true
    success = tunnel.closeTunnel(waitForThreads: waitForThreadExit)
    if success == false {
        print("\(tunnel.lastErrorText!)")
        return
    }


}