Sample code for 30+ languages & platforms
Objective-C

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Objective-C Downloads

Objective-C
#import <CkoSsh.h>
#import <NSString.h>
#import <CkoXml.h>

BOOL success = NO;

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
//  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

CkoSsh *ssh = [[CkoSsh alloc] init];

ssh.ConnectTimeoutMs = [NSNumber numberWithInt:5000];
ssh.ReadTimeoutMs = [NSNumber numberWithInt:15000];

NSString *hostname = @"ssh.example.com";
int port = 22;
success = [ssh Connect: hostname port: [NSNumber numberWithInt: port]];
if (success == NO) {
    NSLog(@"%@",ssh.LastErrorText);
    return;
}

//  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
NSString *xmlResponse = [ssh StartKeyboardAuth: @"mySshLogin"];
if (ssh.LastMethodSuccess == NO) {
    NSLog(@"%@",ssh.LastErrorText);
    return;
}

//  If the server sent a user authentication banner, an application may display it before
//  prompting.
NSLog(@"%@%@",@"UserAuthBanner: ",ssh.UserAuthBanner);

CkoXml *xml = [[CkoXml alloc] init];
success = [xml LoadXml: xmlResponse];
if (success == NO) {
    NSLog(@"%@",xml.LastErrorText);
    return;
}

//  Authentication is complete when the XML contains either a "success" or an "error" node.
if ([xml HasChildWithTag: @"success"]) {
    NSLog(@"%@",@"No password required, already authenticated.");
    return;
}

if ([xml HasChildWithTag: @"error"]) {
    NSLog(@"%@",@"Authentication failed.");
    return;
}

//  Normally you would not hard-code the password in source.  You should instead obtain it
//  from an interactive prompt, environment variable, or a secrets vault.
NSString *password = @"mySshPassword";

//  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
//  prompts, so a robust client loops until it sees "success" or "error".
xmlResponse = [ssh ContinueKeyboardAuth: password];
if (ssh.LastMethodSuccess == NO) {
    NSLog(@"%@",ssh.LastErrorText);
    return;
}

success = [xml LoadXml: xmlResponse];
if (success == NO) {
    NSLog(@"%@",xml.LastErrorText);
    return;
}

if ([xml HasChildWithTag: @"success"]) {
    NSLog(@"%@",@"SSH keyboard-interactive authentication successful.");
    return;
}

if ([xml HasChildWithTag: @"error"]) {
    NSLog(@"%@",@"Authentication failed.");
}