Zig
Zig
SSH Host Key Fingerprint
See more SSH Examples
Demonstrates getting the SSH server's host key fingerprint after connecting. The HostKeyFingerprint property returns the classic MD5 form, while GetHostKeyFP returns a fingerprint using a chosen hash algorithm, with optional inclusion of the key type and hash name.
Background: The host key fingerprint identifies the server, and comparing it against a known-good value is how a client implements host-key pinning — detecting a man-in-the-middle or a server whose key has changed. This is the same fingerprint an SSH client shows on first connection when it asks whether to trust the host. Prefer
SHA256, which is the modern standard; MD5 fingerprints still appear in older tooling but are cryptographically weak.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Demonstrates getting the SSH server's host key fingerprint after connecting.
const ssh = try chilkat.Ssh.init();
defer ssh.deinit();
const hostname = "ssh.example.com";
const port = 22;
ssh.connect(hostname, port) catch {
std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
return;
};
// The classic MD5 fingerprint is available as a property.
const md5_fingerprint = try ssh.getHostKeyFingerprint(alloc);
std.debug.print("{s}\n", .{md5_fingerprint});
// For example: ssh-rsa 3072 21:b0:d8:41:4e:ef:78:10:20:af:01:b7:71:5d:eb:94
// GetHostKeyFP returns a fingerprint using the hash algorithm of your choice, such as SHA256,
// SHA384, or SHA512. The 2nd and 3rd arguments control whether the key type and the hash name
// are included in the returned string.
var include_key_type: bool = true;
var include_hash_name: bool = true;
var sha256_fingerprint: [:0]const u8 = ssh.getHostKeyFP(alloc, "SHA256", include_key_type, include_hash_name) catch {
std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
return;
};
std.debug.print("{s}\n", .{sha256_fingerprint});
// ssh-rsa SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=
include_key_type = false;
include_hash_name = true;
sha256_fingerprint = ssh.getHostKeyFP(alloc, "SHA256", include_key_type, include_hash_name) catch {
std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
return;
};
std.debug.print("{s}\n", .{sha256_fingerprint});
// SHA256:Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=
include_key_type = true;
include_hash_name = false;
sha256_fingerprint = ssh.getHostKeyFP(alloc, "SHA256", include_key_type, include_hash_name) catch {
std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
return;
};
std.debug.print("{s}\n", .{sha256_fingerprint});
// ssh-rsa Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=
include_key_type = false;
include_hash_name = false;
sha256_fingerprint = ssh.getHostKeyFP(alloc, "SHA256", include_key_type, include_hash_name) catch {
std.debug.print("{s}\n", .{try ssh.getLastErrorText(alloc)});
return;
};
std.debug.print("{s}\n", .{sha256_fingerprint});
// Ufgj480OsdsCZRjj9sSNM6fpgIcSJ61RsIG8usndUIY=
ssh.disconnect();
}