Sample code for 30+ languages & platforms
Tcl

Get SSH Server Authentication Methods

See more SSH Examples

Demonstrates getting the authentication methods advertised by an SSH server. Connect first but do not authenticate, then call GetAuthMethods, which returns a lowercase, comma-separated list such as publickey,password,keyboard-interactive.

Important: Querying the authentication methods intentionally disconnects from the server, so reconnect before authenticating.

Background: Knowing what a server accepts lets a client choose the right authentication path rather than guessing — for example, falling back to keyboard-interactive when password authentication is not offered, or failing fast with a clear message when only public-key is allowed. It is also useful diagnostically when authentication fails for reasons that are not obvious from the error text.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  This example requires the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

#  Demonstrates getting the authentication methods advertised by an SSH server.

set ssh [new_CkSsh]

set port 22

#  The server must be connected, but not yet authenticated.
set success [CkSsh_Connect $ssh "ssh.example.com" $port]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $ssh]
    delete_CkSsh $ssh
    exit
}

#  Returns a lowercase, comma-separated list, such as:
#      publickey,password,keyboard-interactive
set authMethods [CkSsh_getAuthMethods $ssh]
if {[CkSsh_get_LastMethodSuccess $ssh] == 0} then {
    puts [CkSsh_lastErrorText $ssh]
    delete_CkSsh $ssh
    exit
}

puts "Authentication methods supported by this server: $authMethods"

#  IMPORTANT: Querying the authentication methods intentionally disconnects from the server.
#  Reconnect before authenticating.
set success [CkSsh_Connect $ssh "ssh.example.com" $port]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $ssh]
    delete_CkSsh $ssh
    exit
}

#  Normally you would not hard-code the password in source.  You should instead obtain it
#  from an interactive prompt, environment variable, or a secrets vault.
set password "mySshPassword"

set success [CkSsh_AuthenticatePw $ssh "mySshLogin" $password]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $ssh]
    delete_CkSsh $ssh
    exit
}

puts "SSH authentication successful."

CkSsh_Disconnect $ssh

delete_CkSsh $ssh