Sample code for 30+ languages & platforms
Zig

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
    // more prompts as XML, and the application answers each with ContinueKeyboardAuth.

    const ssh = try chilkat.Ssh.init();
    defer ssh.deinit();

    ssh.setConnectTimeoutMs(5000);
    ssh.setReadTimeoutMs(15000);

    const hostname = "ssh.example.com";
    const port = 22;
    ssh.connect(hostname, port) catch {
        std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
        return;
    };

    // Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
    var xml_response: [:0]const u8 = ssh.startKeyboardAuth(alloc, "mySshLogin") catch {
        std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
        return;
    };

    // If the server sent a user authentication banner, an application may display it before
    // prompting.
    std.debug.print("UserAuthBanner: {s}\n", .{try ssh.getUserAuthBanner(alloc)});

    const xml = try chilkat.Xml.init();
    defer xml.deinit();
    xml.loadXml(xml_response) catch {
        std.debug.print("{s}\n", .{try xml.getLastErrorText(alloc)});
        return;
    };

    // Authentication is complete when the XML contains either a "success" or an "error" node.
    if (xml.hasChildWithTag("success")) {
        std.debug.print("No password required, already authenticated.\n", .{});
        return;
    }

    if (xml.hasChildWithTag("error")) {
        std.debug.print("Authentication failed.\n", .{});
        return;
    }

    // Normally you would not hard-code the password in source.  You should instead obtain it
    // from an interactive prompt, environment variable, or a secrets vault.
    const password = "mySshPassword";

    // Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
    // prompts, so a robust client loops until it sees "success" or "error".
    xml_response = ssh.continueKeyboardAuth(alloc, password) catch {
        std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
        return;
    };

    xml.loadXml(xml_response) catch {
        std.debug.print("{s}\n", .{try xml.getLastErrorText(alloc)});
        return;
    };

    if (xml.hasChildWithTag("success")) {
        std.debug.print("SSH keyboard-interactive authentication successful.\n", .{});
        return;
    }

    if (xml.hasChildWithTag("error")) {
        std.debug.print("Authentication failed.\n", .{});
    }
}