Sample code for 30+ languages & platforms
Rust

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
// more prompts as XML, and the application answers each with ContinueKeyboardAuth.

let ssh = chilkat::Ssh::new();

ssh.set_connect_timeout_ms(5000);
ssh.set_read_timeout_ms(15000);

let hostname = "ssh.example.com".to_string();
let port = 22;
if ssh.connect(&hostname, port).is_err() {
    println!("{}", ssh.last_error_text());
    return;
}

// Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
let Ok(mut xml_response) = ssh.start_keyboard_auth("mySshLogin") else {
    println!("{}", ssh.last_error_text());
    return;
};

// If the server sent a user authentication banner, an application may display it before
// prompting.
println!("UserAuthBanner: {}", ssh.user_auth_banner());

let xml = chilkat::Xml::new();
if xml.load_xml(&xml_response).is_err() {
    println!("{}", xml.last_error_text());
    return;
}

// Authentication is complete when the XML contains either a "success" or an "error" node.
if xml.has_child_with_tag("success") {
    println!("No password required, already authenticated.");
    return;
}

if xml.has_child_with_tag("error") {
    println!("Authentication failed.");
    return;
}

// Normally you would not hard-code the password in source.  You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
let password = "mySshPassword".to_string();

// Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
// prompts, so a robust client loops until it sees "success" or "error".
xml_response = ssh.continue_keyboard_auth(&password).unwrap_or_default();
if !ssh.last_method_success() {
    println!("{}", ssh.last_error_text());
    return;
}

if xml.load_xml(&xml_response).is_err() {
    println!("{}", xml.last_error_text());
    return;
}

if xml.has_child_with_tag("success") {
    println!("SSH keyboard-interactive authentication successful.");
    return;
}

if xml.has_child_with_tag("error") {
    println!("Authentication failed.");
}