Skip to content

SSHClient for Dyalog APL

SSHClient is a pure-APL SSH-2 client for Dyalog. It implements the SSH-2 protocol (RFC 4251–4254) directly on top of a raw TCP socket: Conga provides the transport, and the cryptography (SHA-256, HMAC-SHA-256, AES-128-CTR, RSA, Diffie–Hellman) is driven through ⎕NA bindings to the nettle/GMP library that ships inside Conga's SSL plugin — so there is nothing to install beyond a standard Dyalog installation.

      client←⎕NEW SSHClient ('server.example.com' 22 'alice' 'secret')
      client.Connect
[rc: 0 | msg:  | host: server.example.com:22 | ≢Data: 0]
      (client.Exec 'uname -sr').Data
Linux 6.6.87
      ⊢file←client.GetFile '/var/log/app.log'
[rc: 0 | msg:  | host: :22 | ≢Data: 11]
      client.Close

What it does

  • Connect — full SSH-2 handshake: banner exchange, algorithm negotiation, Diffie–Hellman group14 key exchange, host-key signature verification, known_hosts trust checking, and AES-CTR + HMAC transport encryption
  • Authenticate — password or RSA public-key authentication
  • Exec — run remote commands and capture stdout
  • SFTP — upload, download, list directories, stat files
  • One-shot — SSHClient.Do connects, runs a command, and disconnects in a single call

Safety

The client verifies the server in two independent ways: the host-key signature proves the server owns the key it presented, and the known_hosts check (on by default, OpenSSH accept-new semantics) proves it is the key the server is supposed to have — a man-in-the-middle presenting its own key is refused before any credentials are sent. The crypto primitives are validated against official NIST/RFC test vectors and cross-checked against OpenSSL by the accompanying test suite. See Security Model for the full picture, including current limitations.

Status

Version 0.1.0. Interoperates with OpenSSH; exercised by a 50-test suite that runs on every push (see Testing & CI). The algorithm set is deliberately small — see Algorithms & Limitations.