Sample code for 30+ languages & platforms
Delphi DLL

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Delphi DLL Downloads

Delphi DLL
var
success: Boolean;
ssh: HCkSsh;
hostname: PWideChar;
port: Integer;
xmlResponse: PWideChar;
xml: HCkXml;
password: PWideChar;

begin
success := False;

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
//  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

ssh := CkSsh_Create();

CkSsh_putConnectTimeoutMs(ssh,5000);
CkSsh_putReadTimeoutMs(ssh,15000);

hostname := 'ssh.example.com';
port := 22;
success := CkSsh_Connect(ssh,hostname,port);
if (success = False) then
  begin
    Memo1.Lines.Add(CkSsh__lastErrorText(ssh));
    Exit;
  end;

//  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
xmlResponse := CkSsh__startKeyboardAuth(ssh,'mySshLogin');
if (CkSsh_getLastMethodSuccess(ssh) = False) then
  begin
    Memo1.Lines.Add(CkSsh__lastErrorText(ssh));
    Exit;
  end;

//  If the server sent a user authentication banner, an application may display it before
//  prompting.
Memo1.Lines.Add('UserAuthBanner: ' + CkSsh__userAuthBanner(ssh));

xml := CkXml_Create();
success := CkXml_LoadXml(xml,xmlResponse);
if (success = False) then
  begin
    Memo1.Lines.Add(CkXml__lastErrorText(xml));
    Exit;
  end;

//  Authentication is complete when the XML contains either a "success" or an "error" node.
if (CkXml_HasChildWithTag(xml,'success')) then
  begin
    Memo1.Lines.Add('No password required, already authenticated.');
    Exit;
  end;

if (CkXml_HasChildWithTag(xml,'error')) then
  begin
    Memo1.Lines.Add('Authentication failed.');
    Exit;
  end;

//  Normally you would not hard-code the password in source.  You should instead obtain it
//  from an interactive prompt, environment variable, or a secrets vault.
password := 'mySshPassword';

//  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
//  prompts, so a robust client loops until it sees "success" or "error".
xmlResponse := CkSsh__continueKeyboardAuth(ssh,password);
if (CkSsh_getLastMethodSuccess(ssh) = False) then
  begin
    Memo1.Lines.Add(CkSsh__lastErrorText(ssh));
    Exit;
  end;

success := CkXml_LoadXml(xml,xmlResponse);
if (success = False) then
  begin
    Memo1.Lines.Add(CkXml__lastErrorText(xml));
    Exit;
  end;

if (CkXml_HasChildWithTag(xml,'success')) then
  begin
    Memo1.Lines.Add('SSH keyboard-interactive authentication successful.');
    Exit;
  end;

if (CkXml_HasChildWithTag(xml,'error')) then
  begin
    Memo1.Lines.Add('Authentication failed.');
  end;

CkSsh_Dispose(ssh);
CkXml_Dispose(xml);