Sample code for 30+ languages & platforms
Tcl

SFTP Authenticate Secure

Demonstrates how to do SFTP password authentication with secure strings.

This example requires Chilkat v9.5.0.71 or greater.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Imagine we've previously saved our encrypted login and password within a JSON config file
# that contains this:

# {
#   "ssh_login": "2+qylFfC56Ck7OQQt/U2/w==",
#   "ssh_password": "5neIq9Jmn0E3p71N6Yc8TA=="
# }

set json [new_CkJsonObject]

CkJsonObject_LoadFile $json "qa_data/passwords/ssh.json"

set crypt [new_CkCrypt2]

# These are the encryption settings we previously used to encrypt the credentials within the JSON config file.
CkCrypt2_put_CryptAlgorithm $crypt "aes"
CkCrypt2_put_CipherMode $crypt "cbc"
CkCrypt2_put_KeyLength $crypt 128
CkCrypt2_SetEncodedKey $crypt "000102030405060708090A0B0C0D0E0F" "hex"
CkCrypt2_SetEncodedIV $crypt "000102030405060708090A0B0C0D0E0F" "hex"
CkCrypt2_put_EncodingMode $crypt "base64"

set ssLogin [new_CkSecureString]

set ssPassword [new_CkSecureString]

# Decrypt to the secure string.  (the strings will still held in memory encrypted, but are now encrypted using
# a randomly generated session key.)
CkCrypt2_DecryptSecureENC $crypt [CkJsonObject_stringOf $json "ssh_login"] $ssLogin
CkCrypt2_DecryptSecureENC $crypt [CkJsonObject_stringOf $json "ssh_password"] $ssPassword

set sftp [new_CkSFtp]

set success [CkSFtp_Connect $sftp "MY-SSH-SERVER-DOMAIN-OR-IP" 22]
if {$success != 1} then {
    puts [CkSFtp_lastErrorText $sftp]
    delete_CkJsonObject $json
    delete_CkCrypt2 $crypt
    delete_CkSecureString $ssLogin
    delete_CkSecureString $ssPassword
    delete_CkSFtp $sftp
    exit
}

# Authenticate using secure strings
set success [CkSFtp_AuthenticateSecPw $sftp $ssLogin $ssPassword]
if {$success != 1} then {
    puts [CkSFtp_lastErrorText $sftp]
    delete_CkJsonObject $json
    delete_CkCrypt2 $crypt
    delete_CkSecureString $ssLogin
    delete_CkSecureString $ssPassword
    delete_CkSFtp $sftp
    exit
}

puts "SFTP Authentication successful."

CkSFtp_Disconnect $sftp

delete_CkJsonObject $json
delete_CkCrypt2 $crypt
delete_CkSecureString $ssLogin
delete_CkSecureString $ssPassword
delete_CkSFtp $sftp