Tcl
Tcl
SSH Set Allowed Algorithms
See more SSH Examples
Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories, in order of preference, and is applied before connecting.
Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities such as the Terrapin attack.
Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm, or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old device. Otherwise the safer default is to let the library's ordering evolve as cryptographic guidance changes.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Demonstrates explicitly setting the algorithms allowed during SSH connection negotiation.
#
# -------------------------------------------------------------------------------------------
# Note: You typically should NOT explicitly set allowed algorithms.
# By default, Chilkat orders algorithms according to best practices and accounts for known
# vulnerabilities such as the "Terrapin Attack". Hard-coding algorithms makes an application
# brittle over time: if a server later changes its allowed algorithms, or if you connect to a
# different server, the client and server may fail to agree on a mutually supported set.
# -------------------------------------------------------------------------------------------
set ssh [new_CkSsh]
set json [new_CkJsonObject]
# Algorithms supported by Chilkat, by category:
#
# Key-exchange: curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256,
# ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group14-sha256,
# diffie-hellman-group16-sha512, diffie-hellman-group18-sha512,
# diffie-hellman-group-exchange-sha256, diffie-hellman-group1-sha1,
# diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1
#
# Host key: ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521,
# rsa-sha2-256, rsa-sha2-512, ssh-rsa, ssh-dss
#
# Cipher: chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes192-ctr, aes128-cbc,
# aes256-cbc, aes192-cbc, aes128-gcm@openssh.com, aes256-gcm@openssh.com, twofish256-cbc,
# twofish128-cbc, blowfish-cbc
#
# MAC: hmac-sha2-256, hmac-sha2-512, hmac-sha2-256-etm@openssh.com,
# hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, hmac-sha1, hmac-ripemd160,
# hmac-sha1-96, hmac-md5
# List the allowed algorithms for each category, in order of preference.
set allowed_kex "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
set allowed_hostKey "ssh-ed25519,ecdsa-sha2-nistp256"
set allowed_cipher "chacha20-poly1305@openssh.com,aes256-ctr"
set allowed_mac "hmac-sha2-256,hmac-sha2-512"
CkJsonObject_UpdateString $json "kex" $allowed_kex
CkJsonObject_UpdateString $json "hostKey" $allowed_hostKey
CkJsonObject_UpdateString $json "cipher" $allowed_cipher
CkJsonObject_UpdateString $json "mac" $allowed_mac
# Apply the allow-list. This must be done before connecting.
set success [CkSsh_SetAllowedAlgorithms $ssh $json]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
delete_CkJsonObject $json
exit
}
set port 22
set success [CkSsh_Connect $ssh "ssh.example.com" $port]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
delete_CkJsonObject $json
exit
}
puts "Connected."
CkSsh_Disconnect $ssh
delete_CkSsh $ssh
delete_CkJsonObject $json