Tcl
Tcl
Get SSH Server Authentication Methods
See more SSH Examples
Demonstrates getting the authentication methods advertised by an SSH server. Connect first but do not authenticate, then call GetAuthMethods, which returns a lowercase, comma-separated list such as publickey,password,keyboard-interactive.
Important: Querying the authentication methods intentionally disconnects from the server, so reconnect before authenticating.
Background: Knowing what a server accepts lets a client choose the right authentication path rather than guessing — for example, falling back to keyboard-interactive when password authentication is not offered, or failing fast with a clear message when only public-key is allowed. It is also useful diagnostically when authentication fails for reasons that are not obvious from the error text.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Demonstrates getting the authentication methods advertised by an SSH server.
set ssh [new_CkSsh]
set port 22
# The server must be connected, but not yet authenticated.
set success [CkSsh_Connect $ssh "ssh.example.com" $port]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
exit
}
# Returns a lowercase, comma-separated list, such as:
# publickey,password,keyboard-interactive
set authMethods [CkSsh_getAuthMethods $ssh]
if {[CkSsh_get_LastMethodSuccess $ssh] == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
exit
}
puts "Authentication methods supported by this server: $authMethods"
# IMPORTANT: Querying the authentication methods intentionally disconnects from the server.
# Reconnect before authenticating.
set success [CkSsh_Connect $ssh "ssh.example.com" $port]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
exit
}
# Normally you would not hard-code the password in source. You should instead obtain it
# from an interactive prompt, environment variable, or a secrets vault.
set password "mySshPassword"
set success [CkSsh_AuthenticatePw $ssh "mySshLogin" $password]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
exit
}
puts "SSH authentication successful."
CkSsh_Disconnect $ssh
delete_CkSsh $ssh