Sample code for 30+ languages & platforms
PowerBuilder

SSH Host Key Fingerprint

See more SSH Examples

Demonstrates getting the SSH server's host key fingerprint after connecting. The HostKeyFingerprint property returns the classic MD5 form, while GetHostKeyFP returns a fingerprint using a chosen hash algorithm, with optional inclusion of the key type and hash name.

Background: The host key fingerprint identifies the server, and comparing it against a known-good value is how a client implements host-key pinning — detecting a man-in-the-middle or a server whose key has changed. This is the same fingerprint an SSH client shows on first connection when it asks whether to trust the host. Prefer SHA256, which is the modern standard; MD5 fingerprints still appear in older tooling but are cryptographically weak.

Chilkat PowerBuilder Downloads

PowerBuilder
integer li_rc
integer li_Success
oleobject loo_Ssh
string ls_Hostname
integer li_Port
string ls_Md5_fingerprint
integer li_IncludeKeyType
integer li_IncludeHashName
string ls_Sha256_fingerprint

li_Success = 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Demonstrates getting the SSH server's host key fingerprint after connecting.

loo_Ssh = create oleobject
li_rc = loo_Ssh.ConnectToNewObject("Chilkat.Ssh")
if li_rc < 0 then
    destroy loo_Ssh
    MessageBox("Error","Connecting to COM object failed")
    return
end if

ls_Hostname = "ssh.example.com"
li_Port = 22
li_Success = loo_Ssh.Connect(ls_Hostname,li_Port)
if li_Success = 0 then
    Write-Debug loo_Ssh.LastErrorText
    destroy loo_Ssh
    return
end if

//  The classic MD5 fingerprint is available as a property.
ls_Md5_fingerprint = loo_Ssh.HostKeyFingerprint
Write-Debug ls_Md5_fingerprint
//  For example:  ssh-rsa 3072 21:b0:d8:41:4e:ef:78:10:20:af:01:b7:71:5d:eb:94

//  GetHostKeyFP returns a fingerprint using the hash algorithm of your choice, such as SHA256,
//  SHA384, or SHA512.  The 2nd and 3rd arguments control whether the key type and the hash name
//  are included in the returned string.
li_IncludeKeyType = 1
li_IncludeHashName = 1
ls_Sha256_fingerprint = loo_Ssh.GetHostKeyFP("SHA256",li_IncludeKeyType,li_IncludeHashName)
if loo_Ssh.LastMethodSuccess = 0 then
    Write-Debug loo_Ssh.LastErrorText
    destroy loo_Ssh
    return
end if

Write-Debug ls_Sha256_fingerprint
//  ssh-rsa SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

li_IncludeKeyType = 0
li_IncludeHashName = 1
ls_Sha256_fingerprint = loo_Ssh.GetHostKeyFP("SHA256",li_IncludeKeyType,li_IncludeHashName)
if loo_Ssh.LastMethodSuccess = 0 then
    Write-Debug loo_Ssh.LastErrorText
    destroy loo_Ssh
    return
end if

Write-Debug ls_Sha256_fingerprint
//  SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

li_IncludeKeyType = 1
li_IncludeHashName = 0
ls_Sha256_fingerprint = loo_Ssh.GetHostKeyFP("SHA256",li_IncludeKeyType,li_IncludeHashName)
if loo_Ssh.LastMethodSuccess = 0 then
    Write-Debug loo_Ssh.LastErrorText
    destroy loo_Ssh
    return
end if

Write-Debug ls_Sha256_fingerprint
//  ssh-rsa Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

li_IncludeKeyType = 0
li_IncludeHashName = 0
ls_Sha256_fingerprint = loo_Ssh.GetHostKeyFP("SHA256",li_IncludeKeyType,li_IncludeHashName)
if loo_Ssh.LastMethodSuccess = 0 then
    Write-Debug loo_Ssh.LastErrorText
    destroy loo_Ssh
    return
end if

Write-Debug ls_Sha256_fingerprint
//  Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=

loo_Ssh.Disconnect()


destroy loo_Ssh