Sample code for 30+ languages & platforms
Unicode C

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Unicode C Downloads

Unicode C
#include <C_CkSshW.h>
#include <C_CkXmlW.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkSshW ssh;
    const wchar_t *hostname;
    int port;
    const wchar_t *xmlResponse;
    HCkXmlW xml;
    const wchar_t *password;

    success = FALSE;

    //  This example requires the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    //  Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
    //  more prompts as XML, and the application answers each with ContinueKeyboardAuth.

    ssh = CkSshW_Create();

    CkSshW_putConnectTimeoutMs(ssh,5000);
    CkSshW_putReadTimeoutMs(ssh,15000);

    hostname = L"ssh.example.com";
    port = 22;
    success = CkSshW_Connect(ssh,hostname,port);
    if (success == FALSE) {
        wprintf(L"%s\n",CkSshW_lastErrorText(ssh));
        CkSshW_Dispose(ssh);
        return;
    }

    //  Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
    xmlResponse = CkSshW_startKeyboardAuth(ssh,L"mySshLogin");
    if (CkSshW_getLastMethodSuccess(ssh) == FALSE) {
        wprintf(L"%s\n",CkSshW_lastErrorText(ssh));
        CkSshW_Dispose(ssh);
        return;
    }

    //  If the server sent a user authentication banner, an application may display it before
    //  prompting.
    wprintf(L"UserAuthBanner: %s\n",CkSshW_userAuthBanner(ssh));

    xml = CkXmlW_Create();
    success = CkXmlW_LoadXml(xml,xmlResponse);
    if (success == FALSE) {
        wprintf(L"%s\n",CkXmlW_lastErrorText(xml));
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    //  Authentication is complete when the XML contains either a "success" or an "error" node.
    if (CkXmlW_HasChildWithTag(xml,L"success")) {
        wprintf(L"No password required, already authenticated.\n");
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    if (CkXmlW_HasChildWithTag(xml,L"error")) {
        wprintf(L"Authentication failed.\n");
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    password = L"mySshPassword";

    //  Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
    //  prompts, so a robust client loops until it sees "success" or "error".
    xmlResponse = CkSshW_continueKeyboardAuth(ssh,password);
    if (CkSshW_getLastMethodSuccess(ssh) == FALSE) {
        wprintf(L"%s\n",CkSshW_lastErrorText(ssh));
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    success = CkXmlW_LoadXml(xml,xmlResponse);
    if (success == FALSE) {
        wprintf(L"%s\n",CkXmlW_lastErrorText(xml));
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    if (CkXmlW_HasChildWithTag(xml,L"success")) {
        wprintf(L"SSH keyboard-interactive authentication successful.\n");
        CkSshW_Dispose(ssh);
        CkXmlW_Dispose(xml);
        return;
    }

    if (CkXmlW_HasChildWithTag(xml,L"error")) {
        wprintf(L"Authentication failed.\n");
    }



    CkSshW_Dispose(ssh);
    CkXmlW_Dispose(xml);

    }