Perl
Perl
SSH Keyboard-Interactive Authentication
See more SSH Examples
Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.
Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.
Chilkat Perl Downloads
use chilkat();
$success = 0;
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Demonstrates keyboard-interactive authentication with an SSH server. The server sends one or
# more prompts as XML, and the application answers each with ContinueKeyboardAuth.
$ssh = chilkat::CkSsh->new();
$ssh->put_ConnectTimeoutMs(5000);
$ssh->put_ReadTimeoutMs(15000);
$hostname = "ssh.example.com";
$port = 22;
$success = $ssh->Connect($hostname,$port);
if ($success == 0) {
print $ssh->lastErrorText() . "\r\n";
exit;
}
# Begin keyboard-interactive authentication. The returned XML describes the server's prompts.
$xmlResponse = $ssh->startKeyboardAuth("mySshLogin");
if ($ssh->get_LastMethodSuccess() == 0) {
print $ssh->lastErrorText() . "\r\n";
exit;
}
# If the server sent a user authentication banner, an application may display it before
# prompting.
print "UserAuthBanner: " . $ssh->userAuthBanner() . "\r\n";
$xml = chilkat::CkXml->new();
$success = $xml->LoadXml($xmlResponse);
if ($success == 0) {
print $xml->lastErrorText() . "\r\n";
exit;
}
# Authentication is complete when the XML contains either a "success" or an "error" node.
if ($xml->HasChildWithTag("success")) {
print "No password required, already authenticated." . "\r\n";
exit;
}
if ($xml->HasChildWithTag("error")) {
print "Authentication failed." . "\r\n";
exit;
}
# Normally you would not hard-code the password in source. You should instead obtain it
# from an interactive prompt, environment variable, or a secrets vault.
$password = "mySshPassword";
# Answer the prompt. Typically one call is enough, but a server may issue several rounds of
# prompts, so a robust client loops until it sees "success" or "error".
$xmlResponse = $ssh->continueKeyboardAuth($password);
if ($ssh->get_LastMethodSuccess() == 0) {
print $ssh->lastErrorText() . "\r\n";
exit;
}
$success = $xml->LoadXml($xmlResponse);
if ($success == 0) {
print $xml->lastErrorText() . "\r\n";
exit;
}
if ($xml->HasChildWithTag("success")) {
print "SSH keyboard-interactive authentication successful." . "\r\n";
exit;
}
if ($xml->HasChildWithTag("error")) {
print "Authentication failed." . "\r\n";
}