SSHClient for Dyalog APL¶
SSHClient is a pure-APL SSH-2 client for Dyalog. It implements the SSH-2
protocol (RFC 4251–4254) directly on top of a raw TCP socket: Conga
provides the transport, and the cryptography (SHA-256, HMAC-SHA-256,
AES-128-CTR, RSA, Diffie–Hellman) is driven through ⎕NA bindings to the
nettle/GMP library that ships inside Conga's SSL plugin — so there is
nothing to install beyond a standard Dyalog installation.
client←⎕NEW SSHClient ('server.example.com' 22 'alice' 'secret')
client.Connect
[rc: 0 | msg: | host: server.example.com:22 | ≢Data: 0]
(client.Exec 'uname -sr').Data
Linux 6.6.87
⊢file←client.GetFile '/var/log/app.log'
[rc: 0 | msg: | host: :22 | ≢Data: 11]
client.Close
What it does¶
- Connect — full SSH-2 handshake: banner exchange, algorithm negotiation, Diffie–Hellman group14 key exchange, host-key signature verification, known_hosts trust checking, and AES-CTR + HMAC transport encryption
- Authenticate — password or RSA public-key authentication
- Exec — run remote commands and capture stdout
- SFTP — upload, download, list directories, stat files
- One-shot —
SSHClient.Doconnects, runs a command, and disconnects in a single call
Safety¶
The client verifies the server in two independent ways: the host-key
signature proves the server owns the key it presented, and the
known_hosts check (on by default, OpenSSH accept-new semantics) proves
it is the key the server is supposed to have — a man-in-the-middle
presenting its own key is refused before any credentials are sent. The
crypto primitives are validated against official NIST/RFC test vectors and
cross-checked against OpenSSL by the accompanying test suite. See
Security Model for the full picture, including current
limitations.
Status¶
Version 0.1.0. Interoperates with OpenSSH; exercised by a 50-test suite that runs on every push (see Testing & CI). The algorithm set is deliberately small — see Algorithms & Limitations.