Ssh Ruby Reference Documentation

CkSsh

Current Version: 11.5.0

Chilkat.Ssh

Connect to SSH servers, authenticate, run commands, open channels, and manage secure sessions.

Chilkat.Ssh is Chilkat's primary SSH client class for applications that need secure remote command execution, shell sessions, channel-based communication, port forwarding, and detailed control over SSH transport behavior. It supports password and public-key authentication, keyboard-interactive authentication, stdout and stderr handling, proxies, host key inspection, algorithm selection, connection reuse, and detailed diagnostics for authentication, transport, channel, and disconnect issues.

SSH connection setup

Connect to SSH servers with configurable timeouts, host key handling, proxy settings, preferred IP behavior, and detailed connection logging.

Authentication options

Authenticate with passwords, private keys, combined password/key workflows, or keyboard-interactive authentication when required by the server.

Remote commands

Execute commands on the server, read stdout and stderr, inspect exit status, and manage command channels.

Shell sessions

Open interactive shell channels for command-line sessions that require ongoing input and output rather than a single command result.

Port forwarding

Open SSH channels for direct TCP/IP forwarding scenarios, such as connecting securely through an SSH server to another host and port.

Algorithm and diagnostics

Control allowed SSH algorithms and use detailed error text, session information, and logs to troubleshoot negotiation or server behavior.

Common pattern: Connect to the SSH server, authenticate, open a command, shell, or forwarding channel, read the channel output until complete, close the channel, and then disconnect. Use algorithm controls and diagnostics when working with strict servers, legacy systems, or security-policy requirements.

Object Creation

obj = Chilkat::CkSsh.new()

Properties

AbortCurrent
# boolVal is a boolean
boolVal = ssh.get_AbortCurrent();
ssh.put_AbortCurrent(boolVal);
Introduced in version 9.5.0.58

Set to true to request that the currently running Chilkat operation abort. This applies to synchronous and asynchronous methods that may block on network or lengthy processing.

When the abort is observed, Chilkat resets the property to false. If no operation is running, it is reset when the next method begins. A synchronous call may be aborted by setting this property from another thread.

top
AuthFailReason
# intVal is an integer
intVal = ssh.get_AuthFailReason();
Introduced in version 9.5.0.52

Contains an authentication failure code after AuthenticatePw, AuthenticatePk, or AuthenticatePwPk fails.

ValueMeaning
1Transport failure. Communication with the server was lost, or a read/write operation failed or timed out.
2Invalid key for public-key authentication. The key is malformed, unsupported, not private, or otherwise unsuitable.
3No mutually supported authentication method was available.
4SSH authentication protocol error. An unexpected or invalid message was received.
5The password or private key was rejected.
6The SSH session is already authenticated.
7The server requires a password change. See PasswordChangeRequested.

top
CaretControl
# boolVal is a boolean
boolVal = ssh.get_CaretControl();
ssh.put_CaretControl(boolVal);
Introduced in version 9.5.0.49

Controls whether caret notation is converted to ASCII control characters in strings passed to SendReqExec and ChannelSendString. The default is false.

When set to true, sequences such as ^C, ^M, and ^? are translated before the text is sent.
Caret  Dec  Hex  Name  Description
^@       0   00   NUL   Null
^A       1   01   SOH   Start of Heading
^B       2   02   STX   Start of Text
^C       3   03   ETX   End of Text
^D       4   04   EOT   End of Transmission
^E       5   05   ENQ   Enquiry
^F       6   06   ACK   Acknowledge
^G       7   07   BEL   Bell
^H       8   08   BS    Backspace
^I       9   09   HT    Horizontal Tab
^J      10   0A   LF    Line Feed
^K      11   0B   VT    Vertical Tab
^L      12   0C   FF    Form Feed
^M      13   0D   CR    Carriage Return
^N      14   0E   SO    Shift Out
^O      15   0F   SI    Shift In
^P      16   10   DLE   Data Link Escape
^Q      17   11   DC1   Device Control One (XON)
^R      18   12   DC2   Device Control Two
^S      19   13   DC3   Device Control Three (XOFF)
^T      20   14   DC4   Device Control Four
^U      21   15   NAK   Negative Acknowledge
^V      22   16   SYN   Synchronous Idle
^W      23   17   ETB   End of Transmission Block
^X      24   18   CAN   Cancel
^Y      25   19   EM    End of Medium
^Z      26   1A   SUB   Substitute
^[      27   1B   ESC   Escape
^\      28   1C   FS    File Separator
^]      29   1D   GS    Group Separator
^^      30   1E   RS    Record Separator
^_      31   1F   US    Unit Separator
^?     127   7F   DEL   Delete

top
ChannelOpenFailCode
# intVal is an integer
intVal = ssh.get_ChannelOpenFailCode();

Contains the SSH channel-open failure code when a request to open a channel is rejected. The values are defined by RFC 4254.

CodeSymbolic name
1SSH_OPEN_ADMINISTRATIVELY_PROHIBITED
2SSH_OPEN_CONNECT_FAILED
3SSH_OPEN_UNKNOWN_CHANNEL_TYPE
4SSH_OPEN_RESOURCE_SHORTAGE

top
ChannelOpenFailReason
# strVal is a string
# ckStr is a CkString
ssh.get_ChannelOpenFailReason(ckStr);
strVal = ssh.channelOpenFailReason();

Contains the descriptive text associated with ChannelOpenFailCode after a channel-open request fails.

top
ClientIdentifier
# strVal is a string
# ckStr is a CkString
ssh.get_ClientIdentifier(ckStr);
strVal = ssh.clientIdentifier();
ssh.put_ClientIdentifier(strVal);

Specifies the SSH client-identification string sent when a connection is established. The default is SSH-2.0-Chilkat_ followed by the Chilkat version, for example SSH-2.0-Chilkat_11.6.0.

The value should begin with SSH-2.0-. A server may disconnect if the identification string is not valid.

top
ClientIpAddress
# strVal is a string
# ckStr is a CkString
ssh.get_ClientIpAddress(ckStr);
strVal = ssh.clientIpAddress();
ssh.put_ClientIpAddress(strVal);

This property is normally left unset. Set it only when the computer has multiple network interfaces or multiple local IP addresses and the application needs to use a specific one.

The value may be a numeric IPv4 or IPv6 address. Do not specify a domain name. When this property is empty, Chilkat and the operating system automatically select the appropriate local address.

The specified address must be available on the local computer and must be compatible with the address family used for the connection. If the address is invalid or unavailable, the connection fails.

This setting applies to all connection paths, including direct SSH connections, HTTP and SOCKS proxy connections, ConnectThroughSsh, and multi-hop SSH connections.

top
ClientPort
# intVal is an integer
intVal = ssh.get_ClientPort();
ssh.put_ClientPort(intVal);
Introduced in version 9.5.0.75

This property is normally left at its default value of 0. In this case, the operating system automatically chooses an unused local port from its ephemeral-port range. Applications should set a specific local port only when a remote system or network policy requires the connection to originate from that port.

When set to a nonzero value, Chilkat requests that exact local port. The connection fails if the port is already in use or is otherwise unavailable. A specifically chosen port might also be temporarily unavailable for reuse after a connection closes because of operating-system TCP connection management. These port-reuse concerns do not normally apply when this property remains 0.

This property applies to all connection paths, including direct SSH connections, HTTP and SOCKS proxy connections, ConnectThroughSsh, and multi-hop SSH connections.

Starting in Chilkat v11.6.0, assigned values must be in the range 0 through 65535. If a negative value or a value greater than 65535 is assigned, it is ignored and the existing property value remains unchanged.

top
ConnectTimeoutMs
# intVal is an integer
intVal = ssh.get_ConnectTimeoutMs();
ssh.put_ConnectTimeoutMs(intVal);

Specifies the maximum number of milliseconds to wait for the remote endpoint to accept the TCP connection.

When a proxy is used, this timeout applies to establishing the TCP connection to the proxy. It does not include the HTTP CONNECT exchange, proxy authentication, or SSH protocol negotiation.

top
DebugLogFilePath
# strVal is a string
# ckStr is a CkString
ssh.get_DebugLogFilePath(ckStr);
strVal = ssh.debugLogFilePath();
ssh.put_DebugLogFilePath(strVal);

If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.

Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.

Possible causes of hangs include:

  • A timeout property set to 0, indicating an infinite timeout.
  • A hang occurring within an event callback in the application code.
  • An internal bug in the Chilkat code causing the hang.

More Information and Examples
top
DisconnectCode
# intVal is an integer
intVal = ssh.get_DisconnectCode();

Contains the reason code from an SSH DISCONNECT message received from the server. The values are defined by RFC 4253.

When connection establishment fails, this property is cleared and does not retain a code from an earlier connection.

CodeSymbolic name
1SSH_DISCONNECT_HOST_NOT_ALLOWED_TO_CONNECT
2SSH_DISCONNECT_PROTOCOL_ERROR
3SSH_DISCONNECT_KEY_EXCHANGE_FAILED
4SSH_DISCONNECT_RESERVED
5SSH_DISCONNECT_MAC_ERROR
6SSH_DISCONNECT_COMPRESSION_ERROR
7SSH_DISCONNECT_SERVICE_NOT_AVAILABLE
8SSH_DISCONNECT_PROTOCOL_VERSION_NOT_SUPPORTED
9SSH_DISCONNECT_HOST_KEY_NOT_VERIFIABLE
10SSH_DISCONNECT_CONNECTION_LOST
11SSH_DISCONNECT_BY_APPLICATION
12SSH_DISCONNECT_TOO_MANY_CONNECTIONS
13SSH_DISCONNECT_AUTH_CANCELLED_BY_USER
14SSH_DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE
15SSH_DISCONNECT_ILLEGAL_USER_NAME

top
DisconnectReason
# strVal is a string
# ckStr is a CkString
ssh.get_DisconnectReason(ckStr);
strVal = ssh.disconnectReason();

Contains the descriptive text sent with the server’s SSH DISCONNECT message. See DisconnectCode for the corresponding RFC 4253 reason code.

When connection establishment fails, this property is cleared and does not retain text from an earlier connection.

top
EnableCompression
# boolVal is a boolean
boolVal = ssh.get_EnableCompression();
ssh.put_EnableCompression(boolVal);
Introduced in version 9.5.0.56

Controls whether SSH compression may be negotiated. The default is true, meaning compression is used when the server supports it.

Some older servers advertise compression but fail when it is enabled. If the server disconnects during or immediately after connection/authentication, try setting this property to false.

top
EnableSecrets
# boolVal is a boolean
boolVal = ssh.get_EnableSecrets();
ssh.put_EnableSecrets(boolVal);
Introduced in version 11.5.0

Enables automatic resolution of secret specification strings from secure operating-system storage. The default is false.

When true, supported password properties and authentication methods may receive a value beginning with !! instead of a literal credential. Chilkat resolves the secret from Windows Credential Manager on Windows or Apple Keychain on macOS.

Secret specification format:

!![appName|]service[|domain]|username

This feature applies to HttpProxyPassword, SocksPassword, AuthenticatePw, and AuthenticatePwPk.

More Information and Examples
top
ForceCipher
# strVal is a string
# ckStr is a CkString
ssh.get_ForceCipher(ckStr);
strVal = ssh.forceCipher();
ssh.put_ForceCipher(strVal);

Restricts SSH cipher negotiation to one cipher or a comma-separated preference list. Leave this property empty to let Chilkat choose the first mutually supported cipher from its normal preference order.

Supported cipher names
chacha20-poly1305@openssh.com
aes128-ctr, aes192-ctr, aes256-ctr
aes128-cbc, aes192-cbc, aes256-cbc
aes128-gcm@openssh.com, aes256-gcm@openssh.com
twofish128-cbc, twofish256-cbc
blowfish-cbc, 3des-cbc
arcfour128, arcfour256
Cipher names must use the exact lowercase spelling shown above. If none of the specified ciphers is supported by the server, Connect fails.

top
HostKeyAlg
# strVal is a string
# ckStr is a CkString
ssh.get_HostKeyAlg(ckStr);
strVal = ssh.hostKeyAlg();
ssh.put_HostKeyAlg(strVal);

Specifies the preferred host-key algorithm used during SSH connection establishment. The default is DSS; set it to RSA only when required for compatibility with a particular server.

Normally this property should be left unchanged.

top
HostKeyFingerprint
# strVal is a string
# ckStr is a CkString
ssh.get_HostKeyFingerprint(ckStr);
strVal = ssh.hostKeyFingerprint();

Contains the server host-key fingerprint after a successful connection. A typical value is:

ssh-rsa 1024 68:ff:d1:4e:6c:ff:d7:b0:d6:58:73:85:07:bc:2e:d5

This property is nonempty only while a valid SSH connection exists. It is empty when no valid connection exists, including after a failed connection attempt.

Use GetHostKeyFP when a specific hash algorithm or output format is required.

More Information and Examples
top
HttpProxyAuthMethod
# strVal is a string
# ckStr is a CkString
ssh.get_HttpProxyAuthMethod(ckStr);
strVal = ssh.httpProxyAuthMethod();
ssh.put_HttpProxyAuthMethod(strVal);

Specifies the authentication method used by an HTTP proxy. Matching is case-insensitive.

ValueBehavior
emptyAutomatically negotiate a supported authentication method with the proxy.
BasicUse HTTP Basic authentication.
NTLMUse NTLM authentication.

Basic and NTLM are the supported methods. Chilkat automatically handles a 407 Proxy Authentication Required response and performs the required authentication exchange.

NTLMv2 is used unless NTLMv1 is explicitly selected by setting Global.DefaultNtlmVersion to 1.

top
HttpProxyDomain
# strVal is a string
# ckStr is a CkString
ssh.get_HttpProxyDomain(ckStr);
strVal = ssh.httpProxyDomain();
ssh.put_HttpProxyDomain(strVal);

Specifies the optional Windows domain used for NTLM authentication with an HTTP proxy.

The value is the legacy Windows NetBIOS domain name. It is not a DNS domain name and is not the workstation name. This property is ignored unless NTLM proxy authentication is used.

top
HttpProxyHostname
# strVal is a string
# ckStr is a CkString
ssh.get_HttpProxyHostname(ckStr);
strVal = ssh.httpProxyHostname();
ssh.put_HttpProxyHostname(strVal);

Specifies the hostname or numeric IP address of an HTTP proxy.

Chilkat uses the HTTP CONNECT method to establish the SSH tunnel through the proxy. The TCP connection to the proxy is not itself protected by TLS for this SSH use case.

The HTTP proxy is used only when SocksVersion is 0, this property is nonempty, and HttpProxyPort is nonzero. A configured SOCKS proxy takes precedence. These settings apply to both Connect and ConnectThroughSsh.

More Information and Examples
top
HttpProxyPassword
# strVal is a string
# ckStr is a CkString
ssh.get_HttpProxyPassword(ckStr);
strVal = ssh.httpProxyPassword();
ssh.put_HttpProxyPassword(strVal);

Specifies the password used to authenticate with an HTTP proxy.

If the proxy requires authentication and this property is empty, the connection fails.

top
HttpProxyPort
# intVal is an integer
intVal = ssh.get_HttpProxyPort();
ssh.put_HttpProxyPort(intVal);

Specifies the HTTP proxy port.

An HTTP proxy is used only when SocksVersion is 0, HttpProxyHostname is nonempty, and this property is nonzero. A configured SOCKS proxy takes precedence.

top
HttpProxyUsername
# strVal is a string
# ckStr is a CkString
ssh.get_HttpProxyUsername(ckStr);
strVal = ssh.httpProxyUsername();
ssh.put_HttpProxyUsername(strVal);

Specifies the username used to authenticate with an HTTP proxy.

If the proxy requires authentication and this property is empty, the connection fails.

More Information and Examples
top
IdleTimeoutMs
# intVal is an integer
intVal = ssh.get_IdleTimeoutMs();
ssh.put_IdleTimeoutMs(intVal);

Specifies the maximum time, in milliseconds, that an SSH operation may remain without send or receive progress. The operation fails when no progress occurs for longer than this interval.

The default is 0, which allows an indefinite wait.

top
IsConnected
# boolVal is a boolean
boolVal = ssh.get_IsConnected();

Indicates Chilkat’s last known connection state. It becomes true after Connect successfully establishes the secure SSH transport. A failed Connect always leaves this property equal to false. It also becomes false after Disconnect or when another method detects that the connection has been lost.

Important: This property does not actively test the socket. A server may have closed an idle connection while this property still reports true. To verify the connection, first check this property and then call SendIgnore.

More Information and Examples
top
KeepSessionLog
# boolVal is a boolean
boolVal = ssh.get_KeepSessionLog();
ssh.put_KeepSessionLog(boolVal);

Controls whether SSH protocol traffic is accumulated in SessionLog. The default is false.

Session logging is intended for diagnostics. When enabled, the log continues to grow as the session proceeds, so disable it when it is no longer needed.

top
LastErrorHtml
# strVal is a string
# ckStr is a CkString
ssh.get_LastErrorHtml(ckStr);
strVal = ssh.lastErrorHtml();

Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorText
# strVal is a string
# ckStr is a CkString
ssh.get_LastErrorText(ckStr);
strVal = ssh.lastErrorText();

Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorXml
# strVal is a string
# ckStr is a CkString
ssh.get_LastErrorXml(ckStr);
strVal = ssh.lastErrorXml();

Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastMethodSuccess
# boolVal is a boolean
boolVal = ssh.get_LastMethodSuccess();
ssh.put_LastMethodSuccess(boolVal);

Indicates the success or failure of the most recent method call: true means success, false means failure. This property remains unchanged by property setters or getters. This method is present to address challenges in checking for null or Nothing returns in certain programming languages. Note: This property does not apply to methods that return integer values or to boolean-returning methods where the boolean does not indicate success or failure.

top
MaxPacketSize
# intVal is an integer
intVal = ssh.get_MaxPacketSize();
ssh.put_MaxPacketSize(intVal);

Specifies the maximum SSH channel packet size advertised in the SSH_MSG_CHANNEL_OPEN message. The default is 8192.

For high-volume transfers, a value such as 32768 may improve performance.

top
NumOpenChannels
# intVal is an integer
intVal = ssh.get_NumOpenChannels();

Returns the number of channels currently open in this SSH session.

top
PasswordChangeRequested
# boolVal is a boolean
boolVal = ssh.get_PasswordChangeRequested();

Indicates that the server rejected password authentication because it requires the user to change the password. This property is set by AuthenticatePw and AuthenticatePwPk.

When true, call the authentication method again and pass both passwords in this form:

|oldPassword|newPassword|

top
PreferIpv6
# boolVal is a boolean
boolVal = ssh.get_PreferIpv6();
ssh.put_PreferIpv6(boolVal);

Controls which address family is selected when DNS resolution for a hostname returns both an IPv4 address and an IPv6 address.

  • When false (the default), Chilkat selects the IPv4 address when one is available.
  • When true, Chilkat selects the IPv6 address when one is available.

This property expresses a preference; it does not prohibit use of the other address family when the preferred family is unavailable.

No address fallback: Chilkat attempts only the first address selected from the DNS results. If that connection attempt fails, it does not automatically try another resolved address or fall back to the other address family. For example, when IPv6 is preferred and the selected IPv6 connection fails, an available IPv4 address is not subsequently tried.

top
ReadTimeoutMs
# intVal is an integer
intVal = ssh.get_ReadTimeoutMs();
ssh.put_ReadTimeoutMs(intVal);

Specifies the maximum total time, in milliseconds, allowed for a read operation, even while data continues to arrive. The default is 0, meaning no total read-time limit.

IdleTimeoutMs limits how long a read may make no progress. ReadTimeoutMs limits the overall duration of the read.

top
ReqExecCharset
# strVal is a string
# ckStr is a CkString
ssh.get_ReqExecCharset(ckStr);
strVal = ssh.reqExecCharset();
ssh.put_ReqExecCharset(strVal);
Introduced in version 9.5.0.47

Specifies the character encoding used for command text sent by SendReqExec, QuickCommand, and QuickCmdSend. The default is ANSI; utf-8 is a common alternative.

top
ServerIdentifier
# strVal is a string
# ckStr is a CkString
ssh.get_ServerIdentifier(ckStr);
strVal = ssh.serverIdentifier();
Introduced in version 9.5.0.71

Contains the SSH server-identification string received during connection establishment. For example:

SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.2

If connection establishment fails, this property is cleared, even if the server identifier was received earlier during the failed attempt. It does not retain a value from a previous connection.

top
SessionLog
# strVal is a string
# ckStr is a CkString
ssh.get_SessionLog(ckStr);
strVal = ssh.sessionLog();

Contains the in-memory SSH session log. Enable logging by setting KeepSessionLog to true.

This property contains log text; it is not a file path.

top
SocksHostname
# strVal is a string
# ckStr is a CkString
ssh.get_SocksHostname(ckStr);
strVal = ssh.socksHostname();
ssh.put_SocksHostname(strVal);

Specifies the SOCKS proxy hostname or IPv4 address. This property is used only when SocksVersion is 4 or 5.

top
SocksPassword
# strVal is a string
# ckStr is a CkString
ssh.get_SocksPassword(ckStr);
strVal = ssh.socksPassword();
ssh.put_SocksPassword(strVal);

Specifies the SOCKS5 password when proxy authentication is required. SOCKS4 does not define password authentication, so this property is ignored for SOCKS4.

top
SocksPort
# intVal is an integer
intVal = ssh.get_SocksPort();
ssh.put_SocksPort(intVal);

Specifies the SOCKS proxy port. The default is 1080. This property is used only when SocksVersion is 4 or 5.

top
SocksUsername
# strVal is a string
# ckStr is a CkString
ssh.get_SocksUsername(ckStr);
strVal = ssh.socksUsername();
ssh.put_SocksUsername(strVal);

Specifies the SOCKS proxy username. This property is used only when SocksVersion is 4 or 5.

top
SocksVersion
# intVal is an integer
intVal = ssh.get_SocksVersion();
ssh.put_SocksVersion(intVal);

Selects whether and how a SOCKS proxy is used.

ValueBehavior
0Do not use a SOCKS proxy. This is the default. Chilkat may still use an HTTP proxy if both HttpProxyHostname and HttpProxyPort are set.
4Connect through a SOCKS4 proxy.
5Connect through a SOCKS5 proxy.
Proxy selection: A SOCKS proxy takes precedence over an HTTP proxy. When this property is 4 or 5, Chilkat uses the configured SOCKS proxy. When it is 0, Chilkat uses an HTTP proxy only if HttpProxyHostname is nonempty and HttpProxyPort is nonzero. Otherwise, Chilkat connects directly to the SSH server.

These proxy settings apply to both Connect and ConnectThroughSsh.

top
SoRcvBuf
# intVal is an integer
intVal = ssh.get_SoRcvBuf();
ssh.put_SoRcvBuf(intVal);

Specifies the socket receive-buffer size. The default is 4194304 bytes. Normally this property should remain unchanged.

When download throughput is unexpectedly low, testing a larger value may help. Values should generally be multiples of 4096.

When a proxy is used, this setting applies to the TCP connection made to the proxy.

top
SoSndBuf
# intVal is an integer
intVal = ssh.get_SoSndBuf();
ssh.put_SoSndBuf(intVal);

Specifies the socket send-buffer size. The default is 262144 bytes. Normally this property should remain unchanged.

When upload throughput is unexpectedly low, testing values such as 524288 or 1048576 may help. Values should generally be multiples of 4096.

When a proxy is used, this setting applies to the TCP connection made to the proxy.

top
StderrToStdout
# boolVal is a boolean
boolVal = ssh.get_StderrToStdout();
ssh.put_StderrToStdout(boolVal);

Controls whether stderr is merged into the normal channel receive buffer. The default is true.

When true, retrieve combined stdout and stderr with GetReceivedData, GetReceivedDataN, GetReceivedText, or GetReceivedTextS. When false, retrieve stderr separately with GetReceivedStderr or GetReceivedStderrText.

Many SSH servers send both streams as ordinary CHANNEL_DATA rather than using CHANNEL_EXTENDED_DATA for stderr. In that case, stdout and stderr cannot be separated regardless of this setting. Check SessionLog to see which packet types the server sent.

top
StripColorCodes
# boolVal is a boolean
boolVal = ssh.get_StripColorCodes();
ssh.put_StripColorCodes(boolVal);
Introduced in version 9.5.0.67

Controls whether terminal color escape sequences are removed from received text. The default is true. Set to false when the application needs the original terminal formatting codes.

top
TcpNoDelay
# boolVal is a boolean
boolVal = ssh.get_TcpNoDelay();
ssh.put_TcpNoDelay(boolVal);

Controls the TCP_NODELAY setting for the underlying TCP connection. The default is true, which disables the Nagle algorithm and generally improves responsiveness when many small messages are exchanged.

When a proxy is used, this setting applies to the TCP connection made to the proxy.

top
UncommonOptions
# strVal is a string
# ckStr is a CkString
ssh.get_UncommonOptions(ckStr);
strVal = ssh.uncommonOptions();
ssh.put_UncommonOptions(strVal);
Introduced in version 9.5.0.73

Provides comma-separated compatibility and security options for uncommon SSH scenarios. The default is an empty string, which is appropriate for most applications.

KeywordEffect
ForceUserAuthRsaSha1Forces ssh-rsa/SHA-1 for RSA user authentication. Set before connecting when a server advertises RSA-SHA2 but still requires the legacy SHA-1 user-auth signature.
no-weak-mac-algsRemoves hmac-sha1-96, hmac-sha1, hmac-md5, and hmac-ripemd160 from the offered MAC algorithms.
ProtectFromVpnOn Android, bypasses an installed or active VPN.
+ssh-hmac-etmRe-enables Encrypt-then-MAC algorithms that are disabled by default as a Terrapin mitigation.
+chacha20-poly1305@openssh.comRe-enables chacha20-poly1305@openssh.com, which is disabled by default as a Terrapin mitigation.
Set connection-negotiation options before calling Connect.

top
UserAuthBanner
# strVal is a string
# ckStr is a CkString
ssh.get_UserAuthBanner(ckStr);
strVal = ssh.userAuthBanner();
ssh.put_UserAuthBanner(strVal);
Introduced in version 9.5.0.46

Contains a user-authentication banner received from the server during keyboard-interactive authentication. Check this property after calling StartKeyboardAuth and display it to the user when appropriate.

top
Utf8
# boolVal is a boolean
boolVal = ssh.get_Utf8();
ssh.put_Utf8(boolVal);

When set to true, all string arguments and return values are interpreted as UTF-8 strings. When set to false, they are interpreted as ANSI strings.

In Chilkat v11.0.0 and later, the default value is true. Before v11.0.0, it was false.

top
VerboseLogging
# boolVal is a boolean
boolVal = ssh.get_VerboseLogging();
ssh.put_VerboseLogging(boolVal);

If set to true, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is false. Verbose logging should only be used for debugging. The potentially large quantity of logged information may adversely affect peformance.

top
Version
# strVal is a string
# ckStr is a CkString
ssh.get_Version(ckStr);
strVal = ssh.version();

Version of the component/library, such as "10.1.0"

More Information and Examples
top

Methods

AuthenticatePk
# username is a string
# privateKey is a CkSshKey
status = ssh.AuthenticatePk(username, privateKey);

Authenticates the connected SSH session using public-key authentication. username identifies the server account, and privateKey supplies the matching private key. The corresponding public key must already be authorized for username on the server.

Call Connect first. After a failure, inspect AuthFailReason and LastErrorText.

Returns true for success, false for failure.

top
AuthenticatePkAsync (1)
# returns a CkTask
# username is a string
# privateKey is a CkSshKey
ret_task = ssh.AuthenticatePkAsync(username, privateKey);

Creates an asynchronous task to call the AuthenticatePk method with the arguments provided.

Returns nil on failure

top
AuthenticatePw
# login is a string
# password is a string
status = ssh.AuthenticatePw(login, password);

Authenticates the connected SSH session using the login in login and the password in password.

A typical sequence is Connect followed by one authentication method. If the server requests a password change, see PasswordChangeRequested.

After a failure, inspect AuthFailReason and LastErrorText.

Returns true for success, false for failure.

top
AuthenticatePwAsync (1)
# returns a CkTask
# login is a string
# password is a string
ret_task = ssh.AuthenticatePwAsync(login, password);

Creates an asynchronous task to call the AuthenticatePw method with the arguments provided.

Returns nil on failure

top
AuthenticatePwPk
# username is a string
# password is a string
# privateKey is a CkSshKey
status = ssh.AuthenticatePwPk(username, password, privateKey);

Authenticates with a server that requires both a password and a private key. username is the username, password is the password, and privateKey is the private key.

Most servers require either password or public-key authentication rather than both. After a failure, inspect AuthFailReason and LastErrorText.

Returns true for success, false for failure.

More Information and Examples
top
AuthenticatePwPkAsync (1)
# returns a CkTask
# username is a string
# password is a string
# privateKey is a CkSshKey
ret_task = ssh.AuthenticatePwPkAsync(username, password, privateKey);

Creates an asynchronous task to call the AuthenticatePwPk method with the arguments provided.

Returns nil on failure

top
AuthenticateSecPw
# login is a CkSecureString
# password is a CkSecureString
status = ssh.AuthenticateSecPw(login, password);
Introduced in version 9.5.0.71

Performs the same password authentication as AuthenticatePw, but receives the login and password in SecureString objects.

Returns true for success, false for failure.

More Information and Examples
top
AuthenticateSecPwAsync (1)
# returns a CkTask
# login is a CkSecureString
# password is a CkSecureString
ret_task = ssh.AuthenticateSecPwAsync(login, password);
Introduced in version 9.5.0.71

Creates an asynchronous task to call the AuthenticateSecPw method with the arguments provided.

Returns nil on failure

top
AuthenticateSecPwPk
# username is a CkSecureString
# password is a CkSecureString
# privateKey is a CkSshKey
status = ssh.AuthenticateSecPwPk(username, password, privateKey);
Introduced in version 9.5.0.71

Performs the same combined password/private-key authentication as AuthenticatePwPk, but receives the username and password in SecureString objects.

Returns true for success, false for failure.

top
AuthenticateSecPwPkAsync (1)
# returns a CkTask
# username is a CkSecureString
# password is a CkSecureString
# privateKey is a CkSshKey
ret_task = ssh.AuthenticateSecPwPkAsync(username, password, privateKey);
Introduced in version 9.5.0.71

Creates an asynchronous task to call the AuthenticateSecPwPk method with the arguments provided.

Returns nil on failure

top
ChannelIsOpen
# channelNum is an integer
retBool = ssh.ChannelIsOpen(channelNum);

Returns true when the channel identified by channelNum is currently open; otherwise returns false.

top
ChannelPoll
# channelNum is an integer
# pollTimeoutMs is an integer
retInt = ssh.ChannelPoll(channelNum, pollTimeoutMs);

Polls the open channel in channelNum for incoming data, waiting at most pollTimeoutMs milliseconds. Data received by this method is placed in the channel’s internal receive buffer.

Return valueMeaning
-1An error occurred. Inspect LastErrorText, IsConnected, and ChannelIsOpen.
-2No additional data arrived before the applicable timeout.
0The channel has received EOF or is already closed.
> 0The number of bytes now available in the channel receive buffer. Retrieve them with a GetReceived* method.
top
ChannelPollAsync (1)
# returns a CkTask
# channelNum is an integer
# pollTimeoutMs is an integer
ret_task = ssh.ChannelPollAsync(channelNum, pollTimeoutMs);

Creates an asynchronous task to call the ChannelPoll method with the arguments provided.

Returns nil on failure

top
ChannelRead
# channelNum is an integer
retInt = ssh.ChannelRead(channelNum);

Reads incoming data from the open channel in channelNum. The first wait is limited by IdleTimeoutMs. Received bytes are accumulated in the channel’s internal receive buffer.

Return valueMeaning
-1An error occurred. Inspect LastErrorText, IsConnected, and ChannelIsOpen.
-2No additional data arrived before the applicable timeout.
0The channel has received EOF or is already closed.
> 0The number of bytes now available in the channel receive buffer. Retrieve them with a GetReceived* method.
top
ChannelReadAsync (1)
# returns a CkTask
# channelNum is an integer
ret_task = ssh.ChannelReadAsync(channelNum);

Creates an asynchronous task to call the ChannelRead method with the arguments provided.

Returns nil on failure

top
ChannelReadAndPoll
# channelNum is an integer
# pollTimeoutMs is an integer
retInt = ssh.ChannelReadAndPoll(channelNum, pollTimeoutMs);

Reads the channel in channelNum and continues reading until no additional data arrives for pollTimeoutMs milliseconds. The first wait uses IdleTimeoutMs; after data begins arriving, each subsequent wait uses pollTimeoutMs.

This pattern is useful for shell commands: allow a longer wait for the first output, then stop shortly after the output stream becomes idle.
Return valueMeaning
-1An error occurred. Inspect LastErrorText, IsConnected, and ChannelIsOpen.
-2No additional data arrived before the applicable timeout.
0The channel has received EOF or is already closed.
> 0The number of bytes now available in the channel receive buffer. Retrieve them with a GetReceived* method.
top
ChannelReadAndPollAsync (1)
# returns a CkTask
# channelNum is an integer
# pollTimeoutMs is an integer
ret_task = ssh.ChannelReadAndPollAsync(channelNum, pollTimeoutMs);

Creates an asynchronous task to call the ChannelReadAndPoll method with the arguments provided.

Returns nil on failure

top
ChannelReadAndPoll2
# channelNum is an integer
# pollTimeoutMs is an integer
# maxNumBytes is an integer
retInt = ssh.ChannelReadAndPoll2(channelNum, pollTimeoutMs, maxNumBytes);

Works like ChannelReadAndPoll, but also returns as soon as the total available received data exceeds maxNumBytes bytes.

top
ChannelReadAndPoll2Async (1)
# returns a CkTask
# channelNum is an integer
# pollTimeoutMs is an integer
# maxNumBytes is an integer
ret_task = ssh.ChannelReadAndPoll2Async(channelNum, pollTimeoutMs, maxNumBytes);

Creates an asynchronous task to call the ChannelReadAndPoll2 method with the arguments provided.

Returns nil on failure

top
ChannelReceivedClose
# channelNum is an integer
retBool = ssh.ChannelReceivedClose(channelNum);

Returns true if an SSH CLOSE message has been received for the channel in channelNum. After CLOSE, the channel is closed in both directions and no more data should be sent.

top
ChannelReceivedEof
# channelNum is an integer
retBool = ssh.ChannelReceivedEof(channelNum);

Returns true if an SSH EOF message has been received for the channel in channelNum. EOF means the server will send no more data, but the client may still send data until the channel is closed.

top
ChannelReceivedExitStatus
# channelNum is an integer
retBool = ssh.ChannelReceivedExitStatus(channelNum);

Returns true if the server has supplied an exit-status value for the channel in channelNum. When true, call GetChannelExitStatus.

top
ChannelReceiveToClose
# channelNum is an integer
status = ssh.ChannelReceiveToClose(channelNum);

Receives data on the channel in channelNum until the server closes the channel. On success, use GetReceivedNumBytes to inspect the buffered byte count and a GetReceived* method to retrieve the data.

Returns true for success, false for failure.

top
ChannelReceiveToCloseAsync (1)
# returns a CkTask
# channelNum is an integer
ret_task = ssh.ChannelReceiveToCloseAsync(channelNum);

Creates an asynchronous task to call the ChannelReceiveToClose method with the arguments provided.

Returns nil on failure

top
ChannelReceiveUntilMatch
# channelNum is an integer
# matchPattern is a string
# charset is a string
# caseSensitive is a boolean
status = ssh.ChannelReceiveUntilMatch(channelNum, matchPattern, charset, caseSensitive);

Receives text on the channel in channelNum until the accumulated text matches the wildcard pattern in matchPattern. For example, *Hello World* waits until that text appears. charset specifies the character encoding, and caseSensitive controls case sensitivity.

The method may read beyond the matched text. Use GetReceivedTextS with the matching substring to remove and return only the text through the match.

Usage notes:
  • Set ReadTimeoutMs to a nonzero value to prevent an indefinite wait.
  • For shell automation, a dumb PTY minimizes terminal escape sequences that may interfere with matching.
  • Consider StderrToStdout; merged stderr can also affect pattern matching.

Returns true for success, false for failure.

top
ChannelReceiveUntilMatchAsync (1)
# returns a CkTask
# channelNum is an integer
# matchPattern is a string
# charset is a string
# caseSensitive is a boolean
ret_task = ssh.ChannelReceiveUntilMatchAsync(channelNum, matchPattern, charset, caseSensitive);

Creates an asynchronous task to call the ChannelReceiveUntilMatch method with the arguments provided.

Returns nil on failure

top
ChannelReceiveUntilMatchN
# channelNum is an integer
# matchPatterns is a CkStringArray
# charset is a string
# caseSensitive is a boolean
status = ssh.ChannelReceiveUntilMatchN(channelNum, matchPatterns, charset, caseSensitive);

Works like ChannelReceiveUntilMatch, but returns when any pattern contained in the StringArray passed in matchPatterns is matched. charset specifies the character encoding, and caseSensitive controls case sensitivity.

Set ReadTimeoutMs to a nonzero value to prevent an indefinite wait when none of the patterns arrives.

Returns true for success, false for failure.

More Information and Examples
top
ChannelReceiveUntilMatchNAsync (1)
# returns a CkTask
# channelNum is an integer
# matchPatterns is a CkStringArray
# charset is a string
# caseSensitive is a boolean
ret_task = ssh.ChannelReceiveUntilMatchNAsync(channelNum, matchPatterns, charset, caseSensitive);

Creates an asynchronous task to call the ChannelReceiveUntilMatchN method with the arguments provided.

Returns nil on failure

top
ChannelRelease
# channelNum is an integer
ssh.ChannelRelease(channelNum);
Introduced in version 9.5.0.44

Releases Chilkat’s internal resources for the channel in channelNum after it has been closed. Channels are released automatically when the Ssh object is disposed, so this method is normally needed only by long-running applications that open and close very large numbers of channels.

top
ChannelSendClose
# channelNum is an integer
status = ssh.ChannelSendClose(channelNum);

Sends an SSH CLOSE message for the channel in channelNum, closing the channel in both directions.

Returns true for success, false for failure.

top
ChannelSendCloseAsync (1)
# returns a CkTask
# channelNum is an integer
ret_task = ssh.ChannelSendCloseAsync(channelNum);

Creates an asynchronous task to call the ChannelSendClose method with the arguments provided.

Returns nil on failure

top
ChannelSendEof
# channelNum is an integer
status = ssh.ChannelSendEof(channelNum);

Sends an SSH EOF message on the channel in channelNum. After EOF is sent, no additional data may be sent on that channel, although data may still be received until the channel closes.

Returns true for success, false for failure.

top
ChannelSendEofAsync (1)
# returns a CkTask
# channelNum is an integer
ret_task = ssh.ChannelSendEofAsync(channelNum);

Creates an asynchronous task to call the ChannelSendEof method with the arguments provided.

Returns nil on failure

top
ChannelSendString
# channelNum is an integer
# textData is a string
# charset is a string
status = ssh.ChannelSendString(channelNum, textData, charset);

Encodes the text in textData using the character set named by charset, then sends the resulting bytes on the channel in channelNum.

See Supported Charsets. When CaretControl is true, caret sequences are translated to control characters before sending.

Returns true for success, false for failure.

top
ChannelSendStringAsync (1)
# returns a CkTask
# channelNum is an integer
# textData is a string
# charset is a string
ret_task = ssh.ChannelSendStringAsync(channelNum, textData, charset);

Creates an asynchronous task to call the ChannelSendString method with the arguments provided.

Returns nil on failure

top
CheckConnection
retBool = ssh.CheckConnection();
Introduced in version 9.5.0.46

Actively checks whether the underlying TCP socket is still connected to the SSH server. Unlike IsConnected, this method performs a connection check rather than returning only the last known state.

top
ClearTtyModes
ssh.ClearTtyModes();

Clears all TTY mode settings previously added with SetTtyMode. The next SendReqPty request will not include those cleared modes.

top
Connect
# domainName is a string
# port is an integer
status = ssh.Connect(domainName, port);

Establishes an SSH connection to domainName on the TCP port specified by port. The domainName may be a DNS hostname or a numeric IPv4 or IPv6 address.

Proxy selection: If SocksVersion is 4 or 5, Chilkat connects through the configured SOCKS proxy. Otherwise, if HttpProxyHostname is nonempty and HttpProxyPort is nonzero, Chilkat connects through the HTTP proxy. If neither condition applies, Chilkat connects directly to the SSH server.

Connection state after success: A successful call means the TCP connection and secure SSH transport are established. The client and server identification strings have been exchanged, key exchange has completed, and the server host key has been received and cryptographically verified as part of the SSH key exchange. User authentication has not yet started, so every newly connected session is unauthenticated. Next call an authentication method such as AuthenticatePw, AuthenticatePk, AuthenticatePwPk, or StartKeyboardAuth.

If this method is called while the object is already connected, Chilkat first disconnects the existing session and then establishes a new connection. This occurs even when connecting again to the same server. The existing connection and its channels are replaced.

The same Ssh object may be reused after Disconnect or after a failed connection attempt. A failed call always leaves IsConnected equal to false. Connection-related property settings remain in effect across disconnects and subsequent connection attempts.

Typical state sequence: disconnected → SSH transport connected → authenticated → channels open. The operations valid in each state follow the SSH protocol.

Supported negotiation algorithms include:

CategoryAlgorithms
Host keyssh-ed25519, rsa-sha2-256, rsa-sha2-512, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, ssh-rsa, ssh-dss
Key exchangecurve25519-sha256, curve25519-sha256@libssh.org, NIST ECDH, DH group 1/14/16/18, and group-exchange SHA-1/SHA-256
CiphersAES CTR/CBC/GCM, Twofish CBC, Blowfish CBC, and optionally chacha20-poly1305@openssh.com
MACSHA-2, SHA-1, RIPEMD-160, MD5, and optionally OpenSSH Encrypt-then-MAC variants
Compressionnone, zlib, and zlib@openssh.com
Connection failures: Every Internet protocol begins with a TCP connection. Firewalls, endpoint security software, network ACLs, routing, proxies, or server-side policy may block the connection before SSH negotiation begins.

Returns true for success, false for failure.

top
ConnectAsync (1)
# returns a CkTask
# domainName is a string
# port is an integer
ret_task = ssh.ConnectAsync(domainName, port);

Creates an asynchronous task to call the Connect method with the arguments provided.

Returns nil on failure

top
ConnectThroughSsh
# ssh is a CkSsh
# hostname is a string
# port is an integer
status = ssh.ConnectThroughSsh(ssh, hostname, port);
Introduced in version 9.5.0.55

Connects to another SSH server through the already connected and authenticated Ssh object in ssh. hostname and port identify the destination host and port.

application  →  first SSH server  →  destination SSH server

After this method succeeds, authenticate separately with the destination server by calling one of its Authenticate* methods.

The proxy properties on this object also apply to this connection. SOCKS takes precedence over HTTP proxy settings, using the same selection rules as Connect.

Returns true for success, false for failure.

More Information and Examples
top
ConnectThroughSshAsync (1)
# returns a CkTask
# ssh is a CkSsh
# hostname is a string
# port is an integer
ret_task = ssh.ConnectThroughSshAsync(ssh, hostname, port);
Introduced in version 9.5.0.55

Creates an asynchronous task to call the ConnectThroughSsh method with the arguments provided.

Returns nil on failure

top
ContinueKeyboardAuth
# response is a string
# outStr is a CkString (output)
status = ssh.ContinueKeyboardAuth(response, outStr);
retStr = ssh.continueKeyboardAuth(response);
Introduced in version 9.5.0.46

Continues keyboard-interactive authentication by submitting the response in response. For a single prompt, response may be the response text. When the preceding information request contains multiple prompts, supply an XML response:

<response>
  <response1>response to first prompt</response1>
  <response2>response to second prompt</response2>
  ...
</response>

The returned XML has one of three forms: authentication success, authentication failure, or another information request containing additional prompts.

<success>success message</success>

<error>error message</error>

<infoRequest numPrompts="N">
  <name>name</name>
  <instruction>instructions</instruction>
  <prompt1 echo="1_or_0">prompt text</prompt1>
  ...
</infoRequest>

Returns true for success, false for failure.

More Information and Examples
top
ContinueKeyboardAuthAsync (1)
# returns a CkTask
# response is a string
ret_task = ssh.ContinueKeyboardAuthAsync(response);
Introduced in version 9.5.0.46

Creates an asynchronous task to call the ContinueKeyboardAuth method with the arguments provided.

Returns nil on failure

top
Disconnect
ssh.Disconnect();

Closes the current SSH connection and releases all open channels associated with the session.

The Ssh object remains reusable. Connection-related property settings are not reset and remain in effect for subsequent calls to Connect. Every newly established connection begins unauthenticated, even if the object authenticated a previous session.

top
GetAuthMethods
# outStr is a CkString (output)
status = ssh.GetAuthMethods(outStr);
retStr = ssh.getAuthMethods();
Introduced in version 9.5.0.78

Queries the connected server for its supported user-authentication methods and returns a comma-separated string such as publickey,password,keyboard-interactive.

Call this method after Connect and before authenticating. The method intentionally disconnects after obtaining the list, so reconnect before attempting authentication.

Returns true for success, false for failure.

More Information and Examples
top
GetAuthMethodsAsync (1)
# returns a CkTask
ret_task = ssh.GetAuthMethodsAsync();
Introduced in version 9.5.0.78

Creates an asynchronous task to call the GetAuthMethods method with the arguments provided.

Returns nil on failure

top
GetChannelExitStatus
# channelNum is an integer
retInt = ssh.GetChannelExitStatus(channelNum);

Returns the exit-status value received for the channel in channelNum. Call this method only after ChannelReceivedExitStatus returns true.

top
GetChannelNumber
# index is an integer
retInt = ssh.GetChannelNumber(index);

Returns the channel number for the open channel at zero-based index index. Use NumOpenChannels to determine the valid index range. Returns -1 when index is out of range.

top
GetChannelType
# index is an integer
# outStr is a CkString (output)
status = ssh.GetChannelType(index, outStr);
retStr = ssh.getChannelType(index);

Returns the type of the open channel at zero-based index index. Possible values include session, x11, forwarded-tcpip, and direct-tcpip.

Returns true for success, false for failure.

top
GetHostKeyFP
# hashAlg is a string
# includeKeyType is a boolean
# includeHashName is a boolean
# outStr is a CkString (output)
status = ssh.GetHostKeyFP(hashAlg, includeKeyType, includeHashName, outStr);
retStr = ssh.getHostKeyFP(hashAlg, includeKeyType, includeHashName);
Introduced in version 9.5.0.92

Returns the connected server’s host-key fingerprint. hashAlg specifies the hash algorithm, such as SHA256, SHA384, SHA512, SHA1, MD5, or a SHA-3 variant. includeKeyType controls whether the host-key type is included; includeHashName controls whether the hash name is included.

includeKeyTypeincludeHashNameExample format
truetruessh-rsa SHA256:L7sQgnpnoBwRoyIYXAFB...
truefalsessh-rsa L7sQgnpnoBwRoyIYXAFB...
falsetrueSHA256:L7sQgnpnoBwRoyIYXAFB...
falsefalseL7sQgnpnoBwRoyIYXAFB...

Possible host-key types include ssh-rsa, ECDSA types such as ecdsa-sha2-nistp256, ssh-ed25519, and ssh-dss.

Returns true for success, false for failure.

More Information and Examples
top
GetLastJsonData
# json is a CkJsonObject
ssh.GetLastJsonData(json);
Introduced in version 9.5.0.79

Copies structured diagnostic information from the most recently called method into the JsonObject in json. Many methods do not produce additional JSON details; in those cases the object may contain little or no information.

top
GetReceivedNumBytes
# channelNum is an integer
retInt = ssh.GetReceivedNumBytes(channelNum);

Returns the number of bytes currently available in the receive buffer for the channel in channelNum. Retrieve the bytes with GetReceivedData, GetReceivedDataN, or a text-retrieval method.

top
GetReceivedStderrText
# channelNum is an integer
# charset is a string
# outStr is a CkString (output)
status = ssh.GetReceivedStderrText(channelNum, charset, outStr);
retStr = ssh.getReceivedStderrText(channelNum, charset);

Decodes and returns all text currently accumulated in the stderr buffer for the channel in channelNum, using the character set in charset. The stderr buffer is cleared after the text is returned.

See Supported Charsets.

Returns true for success, false for failure.

top
GetReceivedText
# channelNum is an integer
# charset is a string
# outStr is a CkString (output)
status = ssh.GetReceivedText(channelNum, charset, outStr);
retStr = ssh.getReceivedText(channelNum, charset);

Decodes and returns all text currently accumulated in the receive buffer for the channel in channelNum, using the character set in charset. The receive buffer is cleared after the text is returned.

See Supported Charsets.

Returns true for success, false for failure.

top
GetReceivedTextS
# channelNum is an integer
# substr is a string
# charset is a string
# outStr is a CkString (output)
status = ssh.GetReceivedTextS(channelNum, substr, charset, outStr);
retStr = ssh.getReceivedTextS(channelNum, substr, charset);

Decodes text in the channel receive buffer and returns only the portion through the first occurrence of substr, inclusive. charset specifies the character set.

The returned portion is removed from the buffer. If substr is not found, an empty string is returned and the buffer is left unchanged.

Returns true for success, false for failure.

top
LoadTaskCaller
# task is a CkTask
status = ssh.LoadTaskCaller(task);
Introduced in version 9.5.0.80

Loads into this object the caller state associated with the asynchronous method represented by task. This is used by generated asynchronous wrappers to recover the object that initiated the task.

Returns true for success, false for failure.

top
OpenCustomChannel
# channelType is a string
retInt = ssh.OpenCustomChannel(channelType);

Requests a custom SSH channel whose application-defined channel type is supplied in channelType. On success, returns the channel number used by subsequent channel methods; returns -1 on failure.

top
OpenCustomChannelAsync (1)
# returns a CkTask
# channelType is a string
ret_task = ssh.OpenCustomChannelAsync(channelType);

Creates an asynchronous task to call the OpenCustomChannel method with the arguments provided.

Returns nil on failure

top
OpenDirectTcpIpChannel
# targetHostname is a string
# targetPort is an integer
retInt = ssh.OpenDirectTcpIpChannel(targetHostname, targetPort);

Opens a direct-tcpip channel through the SSH server to the target host in targetHostname and port in targetPort. Bytes sent with ChannelSend* methods are forwarded to the target; data received from the target is read with ChannelRead* or ChannelReceive* methods.

Returns the new channel number on success, or -1 on failure.

top
OpenDirectTcpIpChannelAsync (1)
# returns a CkTask
# targetHostname is a string
# targetPort is an integer
ret_task = ssh.OpenDirectTcpIpChannelAsync(targetHostname, targetPort);

Creates an asynchronous task to call the OpenDirectTcpIpChannel method with the arguments provided.

Returns nil on failure

top
OpenSessionChannel
retInt = ssh.OpenSessionChannel();

Opens a new SSH session channel. Session channels are used for command execution, shells, PTY requests, environment variables, and related SSH connection-protocol requests.

1. Connect
2. Authenticate
3. OpenSessionChannel
4. SendReqExec or SendReqShell

Returns the new channel number on success, or -1 on failure.

top
OpenSessionChannelAsync (1)
# returns a CkTask
ret_task = ssh.OpenSessionChannelAsync();

Creates an asynchronous task to call the OpenSessionChannel method with the arguments provided.

Returns nil on failure

top
PeekReceivedText
# channelNum is an integer
# charset is a string
# outStr is a CkString (output)
status = ssh.PeekReceivedText(channelNum, charset, outStr);
retStr = ssh.peekReceivedText(channelNum, charset);

Returns the text currently buffered for the channel in channelNum, decoded using charset, without removing it from the receive buffer.

Returns true for success, false for failure.

top
QuickCmdCheck
# pollTimeoutMs is an integer
retInt = ssh.QuickCmdCheck(pollTimeoutMs);
Introduced in version 9.5.0.65

Waits up to pollTimeoutMs milliseconds for any command previously started by QuickCmdSend to complete.

Return valueMeaning
>= 0The channel number of a completed command.
-1No command completed before the timeout.
-2An error occurred, such as loss of the SSH connection.
top
QuickCmdCheckAsync (1)
# returns a CkTask
# pollTimeoutMs is an integer
ret_task = ssh.QuickCmdCheckAsync(pollTimeoutMs);
Introduced in version 9.5.0.65

Creates an asynchronous task to call the QuickCmdCheck method with the arguments provided.

Returns nil on failure

top
QuickCmdSend
# command is a string
retInt = ssh.QuickCmdSend(command);
Introduced in version 9.5.0.65

Starts a remote command and immediately returns its channel number, allowing multiple commands to run concurrently. Internally, this method opens a session channel and sends an exec request.

command is the command. ReqExecCharset controls its encoding. Returns -1 on failure.

top
QuickCmdSendAsync (1)
# returns a CkTask
# command is a string
ret_task = ssh.QuickCmdSendAsync(command);
Introduced in version 9.5.0.65

Creates an asynchronous task to call the QuickCmdSend method with the arguments provided.

Returns nil on failure

top
QuickCommand
# command is a string
# charset is a string
# outStr is a CkString (output)
status = ssh.QuickCommand(command, charset, outStr);
retStr = ssh.quickCommand(command, charset);
Introduced in version 9.5.0.65

Executes one remote command and returns its complete output as text. Internally, this method opens a session channel, sends an exec request, receives until the channel closes, and decodes the buffered output.

command is the command. charset specifies the output character set, such as utf-8 or ansi. ReqExecCharset controls the encoding used to send the command.

Returns true for success, false for failure.

More Information and Examples
top
QuickCommandAsync (1)
# returns a CkTask
# command is a string
# charset is a string
ret_task = ssh.QuickCommandAsync(command, charset);
Introduced in version 9.5.0.65

Creates an asynchronous task to call the QuickCommand method with the arguments provided.

Returns nil on failure

top
QuickShell
retInt = ssh.QuickShell();
Introduced in version 9.5.0.65

Starts a remote shell using the simplified sequence OpenSessionChannelSendReqPtySendReqShell. Returns the shell channel number on success, or -1 on failure.

top
QuickShellAsync (1)
# returns a CkTask
ret_task = ssh.QuickShellAsync();
Introduced in version 9.5.0.65

Creates an asynchronous task to call the QuickShell method with the arguments provided.

Returns nil on failure

top
ReKey
status = ssh.ReKey();

Initiates SSH key re-exchange and waits for it to complete. Either client or server may initiate rekeying at any time.

RFC 4253 recommends changing keys after approximately one gigabyte of transferred data or one hour of connection time, whichever occurs first. In normal use, servers initiate rekeying as needed and Chilkat handles it transparently.

Returns true for success, false for failure.

top
ReKeyAsync (1)
# returns a CkTask
ret_task = ssh.ReKeyAsync();

Creates an asynchronous task to call the ReKey method with the arguments provided.

Returns nil on failure

top
SendIgnore
status = ssh.SendIgnore();

Sends an SSH IGNORE message. The server does not reply, but a successful send helps verify that the connection is still writable. No channel is required.

Returns true for success, false for failure.

More Information and Examples
top
SendIgnoreAsync (1)
# returns a CkTask
ret_task = ssh.SendIgnoreAsync();

Creates an asynchronous task to call the SendIgnore method with the arguments provided.

Returns nil on failure

top
SendReqExec
# channelNum is an integer
# commandLine is a string
status = ssh.SendReqExec(channelNum, commandLine);

Requests execution of the command line in commandLine on the session channel in channelNum. commandLine should contain the complete command and its arguments.

One exec request per channel: An exec channel is used for a single command. The server normally closes it when the command finishes. Open a new session channel before sending another exec request.

This starts a noninteractive command, not a persistent shell. ReqExecCharset controls the encoding of the command text.

Returns true for success, false for failure.

top
SendReqExecAsync (1)
# returns a CkTask
# channelNum is an integer
# commandLine is a string
ret_task = ssh.SendReqExecAsync(channelNum, commandLine);

Creates an asynchronous task to call the SendReqExec method with the arguments provided.

Returns nil on failure

top
SendReqPty
# channelNum is an integer
# termType is a string
# widthInChars is an integer
# heightInChars is an integer
# widthInPixels is an integer
# heightInPixels is an integer
status = ssh.SendReqPty(channelNum, termType, widthInChars, heightInChars, widthInPixels, heightInPixels);

Requests a pseudo-terminal for the session channel in channelNum. termType specifies the terminal type. For character-oriented terminals such as vt100, set widthInChars and heightInChars to the character dimensions and typically set widthInPixels and heightInPixels to 0. For pixel-oriented terminals such as xterm, provide pixel dimensions in widthInPixels and heightInPixels.

For automation that does not need terminal emulation, dumb is often preferable because it minimizes escape sequences in command output.
1. Connect
2. Authenticate
3. OpenSessionChannel
4. SendReqPty, if required
5. SendReqShell

Returns true for success, false for failure.

More Information and Examples
top
SendReqPtyAsync (1)
# returns a CkTask
# channelNum is an integer
# termType is a string
# widthInChars is an integer
# heightInChars is an integer
# widthInPixels is an integer
# heightInPixels is an integer
ret_task = ssh.SendReqPtyAsync(channelNum, termType, widthInChars, heightInChars, widthInPixels, heightInPixels);

Creates an asynchronous task to call the SendReqPty method with the arguments provided.

Returns nil on failure

top
SendReqSetEnv
# channelNum is an integer
# name is a string
# value is a string
status = ssh.SendReqSetEnv(channelNum, name, value);

Requests that the server set the environment variable named by name to the value in value for the session channel in channelNum. The server may accept or reject environment-variable requests according to its configuration.

Returns true for success, false for failure.

top
SendReqSetEnvAsync (1)
# returns a CkTask
# channelNum is an integer
# name is a string
# value is a string
ret_task = ssh.SendReqSetEnvAsync(channelNum, name, value);

Creates an asynchronous task to call the SendReqSetEnv method with the arguments provided.

Returns nil on failure

top
SendReqShell
# channelNum is an integer
status = ssh.SendReqShell(channelNum);

Starts an interactive shell on the open session channel in channelNum. Some servers require a PTY request first; in that case call SendReqPty before this method.

After the shell starts, send commands with ChannelSendString. Include the line ending expected by the remote shell, commonly CRLF.

Returns true for success, false for failure.

More Information and Examples
top
SendReqShellAsync (1)
# returns a CkTask
# channelNum is an integer
ret_task = ssh.SendReqShellAsync(channelNum);

Creates an asynchronous task to call the SendReqShell method with the arguments provided.

Returns nil on failure

top
SendReqSignal
# channelNum is an integer
# signalName is a string
status = ssh.SendReqSignal(channelNum, signalName);

Requests delivery of the signal named by signalName to the remote process running on the channel in channelNum. Supported signal names are:

ABRT  ALRM  FPE  HUP  ILL  INT  KILL
PIPE  QUIT  SEGV TERM USR1 USR2

These are Unix-style signals and are relevant when the SSH server and remote process support them.

Returns true for success, false for failure.

top
SendReqSignalAsync (1)
# returns a CkTask
# channelNum is an integer
# signalName is a string
ret_task = ssh.SendReqSignalAsync(channelNum, signalName);

Creates an asynchronous task to call the SendReqSignal method with the arguments provided.

Returns nil on failure

top
SendReqSubsystem
# channelNum is an integer
# subsystemName is a string
status = ssh.SendReqSubsystem(channelNum, subsystemName);

Requests the predefined subsystem named by subsystemName on the session channel in channelNum. For example, SFTP clients start the sftp subsystem.

Returns true for success, false for failure.

top
SendReqSubsystemAsync (1)
# returns a CkTask
# channelNum is an integer
# subsystemName is a string
ret_task = ssh.SendReqSubsystemAsync(channelNum, subsystemName);

Creates an asynchronous task to call the SendReqSubsystem method with the arguments provided.

Returns nil on failure

top
SendReqWindowChange
# channelNum is an integer
# widthInChars is an integer
# heightInRows is an integer
# pixWidth is an integer
# pixHeight is an integer
retBool = ssh.SendReqWindowChange(channelNum, widthInChars, heightInRows, pixWidth, pixHeight);

Notifies the server that the client-side terminal size changed for the channel in channelNum. widthInChars and heightInRows specify the character dimensions; pixWidth and pixHeight specify the pixel dimensions.

top
SendReqWindowChangeAsync (1)
# returns a CkTask
# channelNum is an integer
# widthInChars is an integer
# heightInRows is an integer
# pixWidth is an integer
# pixHeight is an integer
ret_task = ssh.SendReqWindowChangeAsync(channelNum, widthInChars, heightInRows, pixWidth, pixHeight);

Creates an asynchronous task to call the SendReqWindowChange method with the arguments provided.

Returns nil on failure

top
SendReqX11Forwarding
# channelNum is an integer
# singleConnection is a boolean
# authProt is a string
# authCookie is a string
# screenNum is an integer
retBool = ssh.SendReqX11Forwarding(channelNum, singleConnection, authProt, authCookie, screenNum);

Sends an SSH X11-forwarding request on the session channel in channelNum. singleConnection controls whether forwarding is limited to a single connection; authProt through screenNum provide the X11 authentication protocol, cookie, and screen number.

This low-level method exposes the SSH connection-protocol request. The application is responsible for supplying appropriate X11 values and handling forwarded X11 channels.
top
SendReqX11ForwardingAsync (1)
# returns a CkTask
# channelNum is an integer
# singleConnection is a boolean
# authProt is a string
# authCookie is a string
# screenNum is an integer
ret_task = ssh.SendReqX11ForwardingAsync(channelNum, singleConnection, authProt, authCookie, screenNum);

Creates an asynchronous task to call the SendReqX11Forwarding method with the arguments provided.

Returns nil on failure

top
SendReqXonXoff
# channelNum is an integer
# clientCanDo is a boolean
retBool = ssh.SendReqXonXoff(channelNum, clientCanDo);

Deprecated for practical use. This method should not be used.

top
SendReqXonXoffAsync (1)
# returns a CkTask
# channelNum is an integer
# clientCanDo is a boolean
ret_task = ssh.SendReqXonXoffAsync(channelNum, clientCanDo);

Creates an asynchronous task to call the SendReqXonXoff method with the arguments provided.

Returns nil on failure

top
SetAllowedAlgorithms
# json is a CkJsonObject
status = ssh.SetAllowedAlgorithms(json);
Introduced in version 9.5.0.99

Applies an explicit allow-list of SSH negotiation algorithms supplied in json. Use this method before Connect when security policy or server compatibility requires precise control over accepted host-key, key-exchange, cipher, MAC, or compression algorithms.

Returns true for success, false for failure.

More Information and Examples
top
SetTtyMode
# ttyName is a string
# ttyValue is an integer
retBool = ssh.SetTtyMode(ttyName, ttyValue);

Adds or updates one TTY mode to be included in a later SendReqPty request. ttyName is the mode name and ttyValue is its integer value, commonly 0 or 1. Call this method once for each mode to set.

Supported mode names include:

VINTR VQUIT VERASE VKILL VEOF VEOL VEOL2 VSTART VSTOP
VSUSP VDSUSP VREPRINT VWERASE VLNEXT VFLUSH VSWTCH VSTATUS
VDISCARD IGNPAR PARMRK INPCK ISTRIP INLCR IGNCR ICRNL IUCLC
IXON IXANY IXOFF IMAXBEL ISIG ICANON XCASE ECHO ECHOE ECHOK
ECHONL NOFLSH TOSTOP IEXTEN ECHOCTL ECHOKE PENDIN OPOST OLCUC
ONLCR OCRNL ONOCR ONLRET CS7 CS8 PARENB PARODD
TTY_OP_ISPEED TTY_OP_OSPEED
Most applications do not need to set TTY modes explicitly. Use ClearTtyModes to remove all previously configured modes.
top
StartKeyboardAuth
# login is a string
# outStr is a CkString (output)
status = ssh.StartKeyboardAuth(login, outStr);
retStr = ssh.startKeyboardAuth(login);
Introduced in version 9.5.0.46

Begins keyboard-interactive authentication for the login in login. The returned XML describes the server’s prompts and whether each response should be echoed.

<infoRequest numPrompts="N">
  <name>name</name>
  <instruction>instructions</instruction>
  <prompt1 echo="1_or_0">prompt text</prompt1>
  ...
</infoRequest>

If authentication immediately succeeds or fails, the returned XML instead has one of these forms:

<success>success message</success>

<error>error message</error>

Submit responses with ContinueKeyboardAuth.

Returns true for success, false for failure.

More Information and Examples
top
StartKeyboardAuthAsync (1)
# returns a CkTask
# login is a string
ret_task = ssh.StartKeyboardAuthAsync(login);
Introduced in version 9.5.0.46

Creates an asynchronous task to call the StartKeyboardAuth method with the arguments provided.

Returns nil on failure

top
WaitForChannelMessage
# pollTimeoutMs is an integer
retInt = ssh.WaitForChannelMessage(pollTimeoutMs);
Introduced in version 9.5.0.48

Waits up to pollTimeoutMs milliseconds for an incoming SSH message on any channel. Pass 0 to poll without waiting.

Return valueMeaning
>= 0The channel number on which a message arrived.
-1The wait timed out.
-2Another error occurred, such as a lost connection.
A returned channel number identifies where a message is pending; it does not consume the message. Call an appropriate ChannelRead* or ChannelReceive* method, then retrieve buffered data with a GetReceived* method.
top
WaitForChannelMessageAsync (1)
# returns a CkTask
# pollTimeoutMs is an integer
ret_task = ssh.WaitForChannelMessageAsync(pollTimeoutMs);
Introduced in version 9.5.0.48

Creates an asynchronous task to call the WaitForChannelMessage method with the arguments provided.

Returns nil on failure

top

Deprecated

ChannelSendData Deprecated
# channelNum is an integer
# byteData is a CkByteData
status = ssh.ChannelSendData(channelNum, byteData);

Sends the bytes in byteData on the channel identified by channelNum.

Returns true for success, false for failure.

top
ChannelSendDataAsync Deprecated (1)
# returns a CkTask
# channelNum is an integer
# byteData is a CkByteData
ret_task = ssh.ChannelSendDataAsync(channelNum, byteData);

Creates an asynchronous task to call the ChannelSendData method with the arguments provided.

Returns nil on failure

top
GetReceivedBd Deprecated
# channelNum is an integer
# bd is a CkBinData
status = ssh.GetReceivedBd(channelNum, bd);
Introduced in version 11.4.0

Appends all bytes currently accumulated in the receive buffer for the channel in channelNum to the BinData object in bd, then clears the channel receive buffer.

Returns true for success, false for failure.

top
GetReceivedData Deprecated
# channelNum is an integer
# outBytes is a CkByteData (output)
status = ssh.GetReceivedData(channelNum, outData);

Returns all bytes currently accumulated in the receive buffer for the channel in channelNum, then clears that buffer.

Returns true for success, false for failure.

top
GetReceivedDataN Deprecated
# channelNum is an integer
# maxNumBytes is an integer
# outBytes is a CkByteData (output)
status = ssh.GetReceivedDataN(channelNum, maxNumBytes, outData);

Returns and removes at most maxNumBytes bytes from the receive buffer for the channel in channelNum. Any remaining bytes stay buffered for a later call.

Returns true for success, false for failure.

top
GetReceivedStderr Deprecated
# channelNum is an integer
# outBytes is a CkByteData (output)
status = ssh.GetReceivedStderr(channelNum, outData);
Introduced in version 9.5.0.48

Returns all bytes currently accumulated in the stderr buffer for the channel in channelNum, then clears that stderr buffer.

When StderrToStdout is true—the default—stderr is merged into the normal receive buffer instead.

Returns true for success, false for failure.

top
LastJsonData
# returns a CkJsonObject
ret_jsonObject = ssh.LastJsonData();
Introduced in version 9.5.0.79
This method is deprecated.

Deprecated. Use GetLastJsonData instead.

For methods that provide structured diagnostic details, returns a JsonObject describing what occurred during the most recent operation. Many methods do not produce additional JSON data.

Returns nil on failure

top