Sample code for 30+ languages & platforms
Zig

SFTP Set Allowed SSH Algorithms

See more SFTP Examples

Demonstrates the Chilkat SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH algorithms permitted for the connection. A JsonObject supplies comma-separated allow-lists for the kex, hostKey, cipher, and mac categories. It must be called before Connect.

Important: You typically should not set allowed algorithms explicitly. By default Chilkat orders algorithms according to best practices and accounts for known vulnerabilities.

Background: SSH negotiates a mutually supported algorithm from each category at connection time, and pinning that choice makes an application brittle: if a server later drops a weak algorithm or you point the code at a different server, the two sides may fail to agree and the connection breaks. The legitimate reasons to override are a security policy mandating specific algorithms, or a compatibility problem with an old server. Otherwise the safer default is to let the library's ordering evolve as guidance changes.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // Demonstrates the SFtp.SetAllowedAlgorithms method, which configures the exact set of SSH
    // algorithms permitted for the connection.  The only argument is a JsonObject.  It must be
    // called before Connect.
    //
    // -------------------------------------------------------------------------------------------
    // Note: You typically should NOT explicitly set allowed algorithms.
    // By default, Chilkat orders algorithms according to best practices and accounts for known
    // vulnerabilities such as the "Terrapin Attack".  Hard-coding algorithms can make an
    // application brittle over time: if a server later changes its allowed algorithms, or if you
    // connect to a different server, the client and server may fail to agree on a mutually
    // supported set.
    // -------------------------------------------------------------------------------------------

    const sftp = try chilkat.SFtp.init();
    defer sftp.deinit();

    const json = try chilkat.JsonObject.init();
    defer json.deinit();

    // The algorithms supported by Chilkat, by category:
    //
    // Key-exchange:
    //   curve25519-sha256
    //   curve25519-sha256@libssh.org
    //   ecdh-sha2-nistp256
    //   ecdh-sha2-nistp384
    //   ecdh-sha2-nistp521
    //   diffie-hellman-group14-sha256
    //   diffie-hellman-group16-sha512
    //   diffie-hellman-group18-sha512
    //   diffie-hellman-group-exchange-sha256
    //   diffie-hellman-group1-sha1
    //   diffie-hellman-group14-sha1
    //   diffie-hellman-group-exchange-sha1
    //
    // Host key:
    //   ssh-ed25519
    //   ecdsa-sha2-nistp256
    //   ecdsa-sha2-nistp384
    //   ecdsa-sha2-nistp521
    //   rsa-sha2-256
    //   rsa-sha2-512
    //   ssh-rsa
    //   ssh-dss
    //
    // Cipher (encryption):
    //   chacha20-poly1305@openssh.com
    //   aes128-ctr
    //   aes256-ctr
    //   aes192-ctr
    //   aes128-cbc
    //   aes256-cbc
    //   aes192-cbc
    //   aes128-gcm@openssh.com
    //   aes256-gcm@openssh.com
    //   twofish256-cbc
    //   twofish128-cbc
    //   blowfish-cbc
    //
    // MAC (hash):
    //   hmac-sha2-256
    //   hmac-sha2-512
    //   hmac-sha2-256-etm@openssh.com
    //   hmac-sha2-512-etm@openssh.com
    //   hmac-sha1-etm@openssh.com
    //   hmac-sha1
    //   hmac-ripemd160
    //   hmac-sha1-96
    //   hmac-md5

    // List the allowed key-exchange, host-key, cipher (encryption), and mac (hash) algorithms, in
    // order of preference.
    const allowed_kex = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256";
    const allowed_host_key = "ssh-ed25519,ecdsa-sha2-nistp256";
    const allowed_cipher = "chacha20-poly1305@openssh.com,aes256-ctr";
    const allowed_mac = "hmac-sha2-256,hmac-sha2-512";

    json.updateString("kex", allowed_kex) catch {};
    json.updateString("hostKey", allowed_host_key) catch {};
    json.updateString("cipher", allowed_cipher) catch {};
    json.updateString("mac", allowed_mac) catch {};

    // Apply the allow-list before connecting.
    sftp.setAllowedAlgorithms(json) catch {
        std.debug.print("{s}\n", .{try sftp.getLastErrorText(alloc)});
        return;
    };

    const port = 22;
    sftp.connect("sftp.example.com", port) catch {
        std.debug.print("{s}\n", .{try sftp.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Connected.\n", .{});

    sftp.disconnect();
}