Tcl
Tcl
Continue SSH Tunnel Keyboard-Interactive Authentication
See more SSH Tunnel Examples
Demonstrates the Chilkat SshTunnel.ContinueKeyboardAuth method, which submits a response to a keyboard-interactive prompt. The only argument is the response text; for a request with multiple prompts, an XML response is supplied instead. It returns XML indicating the next prompt or the final result.
Background: This is the second half of the exchange started by
StartKeyboardAuth. A server may issue several rounds of prompts, so a robust client loops: submit answers, read the returned XML, and continue until it sees success or failure. On success, BeginAccepting still must be called before the tunnel forwards traffic.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# Demonstrates the SshTunnel.ContinueKeyboardAuth method, which submits a response to a
# keyboard-interactive prompt. The only argument is the response. For multiple prompts, an XML
# response is supplied instead.
set tunnel [new_CkSshTunnel]
# The tunnel forwards accepted local connections to this destination through the SSH server.
CkSshTunnel_put_DestHostname $tunnel "db.internal.example.com"
CkSshTunnel_put_DestPort $tunnel 5432
# Connect to the SSH server. This performs the TCP/proxy connection and SSH handshake, but
# does not authenticate yet.
set sshPort 22
set success [CkSshTunnel_Connect $tunnel "ssh.example.com" $sshPort]
if {$success == 0} then {
puts [CkSshTunnel_lastErrorText $tunnel]
delete_CkSshTunnel $tunnel
exit
}
# Begin keyboard-interactive authentication to receive the server's prompt(s).
set infoRequestXml [CkSshTunnel_startKeyboardAuth $tunnel "mySshLogin"]
if {[CkSshTunnel_get_LastMethodSuccess $tunnel] == 0} then {
puts [CkSshTunnel_lastErrorText $tunnel]
delete_CkSshTunnel $tunnel
exit
}
# Normally you would not hard-code the password in source. You should instead obtain it
# from an interactive prompt, environment variable, or a secrets vault.
set password "mySshPassword"
# Submit the response (typically the password). The returned XML indicates the next prompt or
# the final result.
set result [CkSshTunnel_continueKeyboardAuth $tunnel $password]
if {[CkSshTunnel_get_LastMethodSuccess $tunnel] == 0} then {
puts [CkSshTunnel_lastErrorText $tunnel]
delete_CkSshTunnel $tunnel
exit
}
puts "$result"
set waitForThreadExit 1
set success [CkSshTunnel_CloseTunnel $tunnel $waitForThreadExit]
if {$success == 0} then {
puts [CkSshTunnel_lastErrorText $tunnel]
delete_CkSshTunnel $tunnel
exit
}
delete_CkSshTunnel $tunnel