Sample code for 30+ languages & platforms
Visual FoxPro

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Visual FoxPro Downloads

Visual FoxPro
LOCAL lnSuccess
LOCAL loSsh
LOCAL lcHostname
LOCAL lnPort
LOCAL lcXmlResponse
LOCAL loXml
LOCAL lcPassword

lnSuccess = 0

*  This example requires the Chilkat API to have been previously unlocked.
*  See Global Unlock Sample for sample code.

*  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
*  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

loSsh = CreateObject('Chilkat.Ssh')

loSsh.ConnectTimeoutMs = 5000
loSsh.ReadTimeoutMs = 15000

lcHostname = "ssh.example.com"
lnPort = 22
lnSuccess = loSsh.Connect(lcHostname,lnPort)
IF (lnSuccess = 0) THEN
    ? loSsh.LastErrorText
    RELEASE loSsh
    CANCEL
ENDIF

*  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
lcXmlResponse = loSsh.StartKeyboardAuth("mySshLogin")
IF (loSsh.LastMethodSuccess = 0) THEN
    ? loSsh.LastErrorText
    RELEASE loSsh
    CANCEL
ENDIF

*  If the server sent a user authentication banner, an application may display it before
*  prompting.
? "UserAuthBanner: " + loSsh.UserAuthBanner

loXml = CreateObject('Chilkat.Xml')
lnSuccess = loXml.LoadXml(lcXmlResponse)
IF (lnSuccess = 0) THEN
    ? loXml.LastErrorText
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

*  Authentication is complete when the XML contains either a "success" or an "error" node.
IF (loXml.HasChildWithTag("success")) THEN
    ? "No password required, already authenticated."
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

IF (loXml.HasChildWithTag("error")) THEN
    ? "Authentication failed."
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

*  Normally you would not hard-code the password in source.  You should instead obtain it
*  from an interactive prompt, environment variable, or a secrets vault.
lcPassword = "mySshPassword"

*  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
*  prompts, so a robust client loops until it sees "success" or "error".
lcXmlResponse = loSsh.ContinueKeyboardAuth(lcPassword)
IF (loSsh.LastMethodSuccess = 0) THEN
    ? loSsh.LastErrorText
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

lnSuccess = loXml.LoadXml(lcXmlResponse)
IF (lnSuccess = 0) THEN
    ? loXml.LastErrorText
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

IF (loXml.HasChildWithTag("success")) THEN
    ? "SSH keyboard-interactive authentication successful."
    RELEASE loSsh
    RELEASE loXml
    CANCEL
ENDIF

IF (loXml.HasChildWithTag("error")) THEN
    ? "Authentication failed."
ENDIF

RELEASE loSsh
RELEASE loXml