Sample code for 30+ languages & platforms
Xbase++

SFTP Set Allowed SSH Algorithms

See more SFTP Examples

Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oSftp
LOCAL oJson
LOCAL cAllowed_kex
LOCAL cAllowed_hostKey
LOCAL cAllowed_cipher
LOCAL cAllowed_mac
LOCAL nPort

nSuccess := 0

//  Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
//  algorithms permitted for the connection.  The only argument is a JsonObject.  It must be
//  called before Connect.
//  
//  -------------------------------------------------------------------------------------------
//  Note: You typically should NOT explicitly set allowed algorithms.
//  By default, Chilkat orders algorithms according to best practices and accounts for known
//  vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms can make an
//  application brittle over time: if a server later changes its allowed algorithms, or if you
//  connect to a different server, the client and server may fail to agree on a mutually
//  supported set.
//  -------------------------------------------------------------------------------------------

oSftp := CreateObject("Chilkat.SFtp")

oJson := CreateObject("Chilkat.JsonObject")

//  The algorithms supported by Chilkat, by category:
//  
//  Key-exchange:
//    curve25519-sha256
//    curve25519-sha256@libssh.org
//    ecdh-sha2-nistp256
//    ecdh-sha2-nistp384
//    ecdh-sha2-nistp521
//    diffie-hellman-group14-sha256
//    diffie-hellman-group16-sha512
//    diffie-hellman-group18-sha512
//    diffie-hellman-group-exchange-sha256
//    diffie-hellman-group1-sha1
//    diffie-hellman-group14-sha1
//    diffie-hellman-group-exchange-sha1
//  
//  Host key:
//    ssh-ed25519
//    ecdsa-sha2-nistp256
//    ecdsa-sha2-nistp384
//    ecdsa-sha2-nistp521
//    rsa-sha2-256
//    rsa-sha2-512
//    ssh-rsa
//    ssh-dss
//  
//  Cipher (encryption):
//    chacha20-poly1305@openssh.com
//    aes128-ctr
//    aes256-ctr
//    aes192-ctr
//    aes128-cbc
//    aes256-cbc
//    aes192-cbc
//    aes128-gcm@openssh.com
//    aes256-gcm@openssh.com
//    twofish256-cbc
//    twofish128-cbc
//    blowfish-cbc
//  
//  MAC (hash):
//    hmac-sha2-256
//    hmac-sha2-512
//    hmac-sha2-256-etm@openssh.com
//    hmac-sha2-512-etm@openssh.com
//    hmac-sha1-etm@openssh.com
//    hmac-sha1
//    hmac-ripemd160
//    hmac-sha1-96
//    hmac-md5

//  List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
//  order of preference.
cAllowed_kex := "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
cAllowed_hostKey := "ssh-ed25519,ecdsa-sha2-nistp256"
cAllowed_cipher := "chacha20-poly1305@openssh.com,aes256-ctr"
cAllowed_mac := "hmac-sha2-256,hmac-sha2-512"

oJson:UpdateString("kex", cAllowed_kex)
oJson:UpdateString("hostKey", cAllowed_hostKey)
oJson:UpdateString("cipher", cAllowed_cipher)
oJson:UpdateString("mac", cAllowed_mac)

//  Apply the allow-list before connecting.
nSuccess := oSftp:SetAllowedAlgorithms(oJson)
IF (nSuccess == 0)
    ? oSftp:LastErrorText
    oSftp:destroy()
    oJson:destroy()
    RETURN
ENDIF

nPort := 22
nSuccess := oSftp:Connect("sftp.example.com", nPort)
IF (nSuccess == 0)
    ? oSftp:LastErrorText
    oSftp:destroy()
    oJson:destroy()
    RETURN
ENDIF

? "Connected."

oSftp:Disconnect()

oSftp:destroy()
oJson:destroy()