Tcl
Tcl
SFTP Authenticate Secure
Demonstrates how to do SFTP password authentication with secure strings.This example requires Chilkat v9.5.0.71 or greater.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Imagine we've previously saved our encrypted login and password within a JSON config file
# that contains this:
# {
# "ssh_login": "2+qylFfC56Ck7OQQt/U2/w==",
# "ssh_password": "5neIq9Jmn0E3p71N6Yc8TA=="
# }
set json [new_CkJsonObject]
CkJsonObject_LoadFile $json "qa_data/passwords/ssh.json"
set crypt [new_CkCrypt2]
# These are the encryption settings we previously used to encrypt the credentials within the JSON config file.
CkCrypt2_put_CryptAlgorithm $crypt "aes"
CkCrypt2_put_CipherMode $crypt "cbc"
CkCrypt2_put_KeyLength $crypt 128
CkCrypt2_SetEncodedKey $crypt "000102030405060708090A0B0C0D0E0F" "hex"
CkCrypt2_SetEncodedIV $crypt "000102030405060708090A0B0C0D0E0F" "hex"
CkCrypt2_put_EncodingMode $crypt "base64"
set ssLogin [new_CkSecureString]
set ssPassword [new_CkSecureString]
# Decrypt to the secure string. (the strings will still held in memory encrypted, but are now encrypted using
# a randomly generated session key.)
CkCrypt2_DecryptSecureENC $crypt [CkJsonObject_stringOf $json "ssh_login"] $ssLogin
CkCrypt2_DecryptSecureENC $crypt [CkJsonObject_stringOf $json "ssh_password"] $ssPassword
set sftp [new_CkSFtp]
set success [CkSFtp_Connect $sftp "MY-SSH-SERVER-DOMAIN-OR-IP" 22]
if {$success != 1} then {
puts [CkSFtp_lastErrorText $sftp]
delete_CkJsonObject $json
delete_CkCrypt2 $crypt
delete_CkSecureString $ssLogin
delete_CkSecureString $ssPassword
delete_CkSFtp $sftp
exit
}
# Authenticate using secure strings
set success [CkSFtp_AuthenticateSecPw $sftp $ssLogin $ssPassword]
if {$success != 1} then {
puts [CkSFtp_lastErrorText $sftp]
delete_CkJsonObject $json
delete_CkCrypt2 $crypt
delete_CkSecureString $ssLogin
delete_CkSecureString $ssPassword
delete_CkSFtp $sftp
exit
}
puts "SFTP Authentication successful."
CkSFtp_Disconnect $sftp
delete_CkJsonObject $json
delete_CkCrypt2 $crypt
delete_CkSecureString $ssLogin
delete_CkSecureString $ssPassword
delete_CkSFtp $sftp