Sample code for 30+ languages & platforms
Xbase++

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oSsh
LOCAL cHostname
LOCAL nPort
LOCAL cXmlResponse
LOCAL oXml
LOCAL cPassword

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
//  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

oSsh := CreateObject("Chilkat.Ssh")

oSsh:ConnectTimeoutMs := 5000
oSsh:ReadTimeoutMs := 15000

cHostname := "ssh.example.com"
nPort := 22
nSuccess := oSsh:Connect(cHostname, nPort)
IF (nSuccess == 0)
    ? oSsh:LastErrorText
    oSsh:destroy()
    RETURN
ENDIF

//  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
cXmlResponse := oSsh:StartKeyboardAuth("mySshLogin")
IF (oSsh:LastMethodSuccess == 0)
    ? oSsh:LastErrorText
    oSsh:destroy()
    RETURN
ENDIF

//  If the server sent a user authentication banner, an application may display it before
//  prompting.
? "UserAuthBanner: " + oSsh:UserAuthBanner

oXml := CreateObject("Chilkat.Xml")
nSuccess := oXml:LoadXml(cXmlResponse)
IF (nSuccess == 0)
    ? oXml:LastErrorText
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

//  Authentication is complete when the XML contains either a "success" or an "error" node.
IF (oXml:HasChildWithTag("success"))
    ? "No password required, already authenticated."
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

IF (oXml:HasChildWithTag("error"))
    ? "Authentication failed."
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

//  Normally you would not hard-code the password in source.  You should instead obtain it
//  from an interactive prompt, environment variable, or a secrets vault.
cPassword := "mySshPassword"

//  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
//  prompts, so a robust client loops until it sees "success" or "error".
cXmlResponse := oSsh:ContinueKeyboardAuth(cPassword)
IF (oSsh:LastMethodSuccess == 0)
    ? oSsh:LastErrorText
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

nSuccess := oXml:LoadXml(cXmlResponse)
IF (nSuccess == 0)
    ? oXml:LastErrorText
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

IF (oXml:HasChildWithTag("success"))
    ? "SSH keyboard-interactive authentication successful."
    oSsh:destroy()
    oXml:destroy()
    RETURN
ENDIF

IF (oXml:HasChildWithTag("error"))
    ? "Authentication failed."
ENDIF

oSsh:destroy()
oXml:destroy()