Delphi ActiveX
Delphi ActiveX
SSH Keyboard-Interactive Authentication
See more SSH Examples
Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.
Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.
Chilkat Delphi ActiveX Downloads
var
success: Integer;
ssh: TChilkatSsh;
hostname: WideString;
port: Integer;
xmlResponse: WideString;
xml: TChilkatXml;
password: WideString;
begin
success := 0;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Demonstrates keyboard-interactive authentication with an SSH server. The server sends one or
// more prompts as XML, and the application answers each with ContinueKeyboardAuth.
ssh := TChilkatSsh.Create(Self);
ssh.ConnectTimeoutMs := 5000;
ssh.ReadTimeoutMs := 15000;
hostname := 'ssh.example.com';
port := 22;
success := ssh.Connect(hostname,port);
if (success = 0) then
begin
Memo1.Lines.Add(ssh.LastErrorText);
Exit;
end;
// Begin keyboard-interactive authentication. The returned XML describes the server's prompts.
xmlResponse := ssh.StartKeyboardAuth('mySshLogin');
if (ssh.LastMethodSuccess = 0) then
begin
Memo1.Lines.Add(ssh.LastErrorText);
Exit;
end;
// If the server sent a user authentication banner, an application may display it before
// prompting.
Memo1.Lines.Add('UserAuthBanner: ' + ssh.UserAuthBanner);
xml := TChilkatXml.Create(Self);
success := xml.LoadXml(xmlResponse);
if (success = 0) then
begin
Memo1.Lines.Add(xml.LastErrorText);
Exit;
end;
// Authentication is complete when the XML contains either a "success" or an "error" node.
if (xml.HasChildWithTag('success')) then
begin
Memo1.Lines.Add('No password required, already authenticated.');
Exit;
end;
if (xml.HasChildWithTag('error')) then
begin
Memo1.Lines.Add('Authentication failed.');
Exit;
end;
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
password := 'mySshPassword';
// Answer the prompt. Typically one call is enough, but a server may issue several rounds of
// prompts, so a robust client loops until it sees "success" or "error".
xmlResponse := ssh.ContinueKeyboardAuth(password);
if (ssh.LastMethodSuccess = 0) then
begin
Memo1.Lines.Add(ssh.LastErrorText);
Exit;
end;
success := xml.LoadXml(xmlResponse);
if (success = 0) then
begin
Memo1.Lines.Add(xml.LastErrorText);
Exit;
end;
if (xml.HasChildWithTag('success')) then
begin
Memo1.Lines.Add('SSH keyboard-interactive authentication successful.');
Exit;
end;
if (xml.HasChildWithTag('error')) then
begin
Memo1.Lines.Add('Authentication failed.');
end;