Tcl
Tcl
SSH Public Key Authentication
See more SSH Examples
Demonstrates authenticating with an SSH server using public-key authentication. A private key is loaded into an SshKey object and passed to AuthenticatePk. The matching public key must already be installed on the server for the account.
Note: The private-key path is relative to the application's current working directory. Supply the path to your own key file.
Background: Public-key authentication is the standard for unattended and automated SSH: the private key never leaves the client, the server merely trusts the corresponding public key, and no reusable password crosses the wire.
SshKey imports several formats — OpenSSH PEM keys via FromOpenSshPrivateKey and PuTTY .ppk files via FromPuttyPrivateKey — encrypted or not. For an encrypted key, set the Password property before importing. Note that LoadText is only a convenience for reading a text file into a string; it does not itself load the key.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Demonstrates authenticating with an SSH server using public-key authentication. The matching
# public key must already be installed on the SSH server for the account.
set ssh [new_CkSsh]
# Timeouts, in milliseconds.
CkSsh_put_ConnectTimeoutMs $ssh 5000
CkSsh_put_ReadTimeoutMs $ssh 15000
set hostname "ssh.example.com"
set port 22
set success [CkSsh_Connect $ssh $hostname $port]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
exit
}
# LoadText is a convenience method that reads any text file into a string. It does not itself
# load the key.
set key [new_CkSshKey]
set privKeyText [CkSshKey_loadText $key "qa_data/my_private_key.pem"]
if {[CkSshKey_get_LastMethodSuccess $key] == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSsh $ssh
delete_CkSshKey $key
exit
}
# Import the private key. Both OpenSSH and PuTTY formats are supported, encrypted or not.
# This example loads an unencrypted OpenSSH-format key; for a PuTTY .ppk file, call
# FromPuttyPrivateKey instead. For an encrypted key, set key.Password before importing.
set success [CkSshKey_FromOpenSshPrivateKey $key $privKeyText]
if {$success == 0} then {
puts [CkSshKey_lastErrorText $key]
delete_CkSsh $ssh
delete_CkSshKey $key
exit
}
set success [CkSsh_AuthenticatePk $ssh "mySshLogin" $key]
if {$success == 0} then {
puts [CkSsh_lastErrorText $ssh]
delete_CkSsh $ssh
delete_CkSshKey $key
exit
}
puts "Public-key authentication successful."
CkSsh_Disconnect $ssh
delete_CkSsh $ssh
delete_CkSshKey $key