Sample code for 30+ languages & platforms
Classic ASP

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Classic ASP Downloads

Classic ASP
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<%
success = 0

'  This example requires the Chilkat API to have been previously unlocked.
'  See Global Unlock Sample for sample code.

'  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
'  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

set ssh = Server.CreateObject("Chilkat.Ssh")

ssh.ConnectTimeoutMs = 5000
ssh.ReadTimeoutMs = 15000

hostname = "ssh.example.com"
port = 22
success = ssh.Connect(hostname,port)
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( ssh.LastErrorText) & "</pre>"
    Response.End
End If

'  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
xmlResponse = ssh.StartKeyboardAuth("mySshLogin")
If (ssh.LastMethodSuccess = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( ssh.LastErrorText) & "</pre>"
    Response.End
End If

'  If the server sent a user authentication banner, an application may display it before
'  prompting.
Response.Write "<pre>" & Server.HTMLEncode( "UserAuthBanner: " & ssh.UserAuthBanner) & "</pre>"

set xml = Server.CreateObject("Chilkat.Xml")
success = xml.LoadXml(xmlResponse)
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( xml.LastErrorText) & "</pre>"
    Response.End
End If

'  Authentication is complete when the XML contains either a "success" or an "error" node.
If (xml.HasChildWithTag("success")) Then
    Response.Write "<pre>" & Server.HTMLEncode( "No password required, already authenticated.") & "</pre>"
    Response.End
End If

If (xml.HasChildWithTag("error")) Then
    Response.Write "<pre>" & Server.HTMLEncode( "Authentication failed.") & "</pre>"
    Response.End
End If

'  Normally you would not hard-code the password in source.  You should instead obtain it
'  from an interactive prompt, environment variable, or a secrets vault.
password = "mySshPassword"

'  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
'  prompts, so a robust client loops until it sees "success" or "error".
xmlResponse = ssh.ContinueKeyboardAuth(password)
If (ssh.LastMethodSuccess = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( ssh.LastErrorText) & "</pre>"
    Response.End
End If

success = xml.LoadXml(xmlResponse)
If (success = 0) Then
    Response.Write "<pre>" & Server.HTMLEncode( xml.LastErrorText) & "</pre>"
    Response.End
End If

If (xml.HasChildWithTag("success")) Then
    Response.Write "<pre>" & Server.HTMLEncode( "SSH keyboard-interactive authentication successful.") & "</pre>"
    Response.End
End If

If (xml.HasChildWithTag("error")) Then
    Response.Write "<pre>" & Server.HTMLEncode( "Authentication failed.") & "</pre>"
End If


%>
</body>
</html>