This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 12 · Mar 16 – 22, 2026

x/crypto/ssh: add AuthCallback to ClientConfig

Worth knowingecosystem

What changed
ssh.ClientConfig now has an AuthCallback that is invoked before each authentication attempt, receiving a ClientAuthContext with metadata, algorithms, allowed methods, partial successes, and tried methods.
Production impact
The source does not say.
Try it
Set AuthCallback to a function that logs the AllowedMethods before each attempt.
Source
github.com/golang/go/issues/76146

Understand it, then run it

The ssh.ClientConfig type in the x/crypto/ssh package now has a new field called AuthCallback. When a program connects to an SSH server, the library normally tries a list of authentication methods that the programmer supplied. With AuthCallback the program can run a small piece of code before each authentication attempt. That code receives information about the server, what methods it accepts, and which methods have already succeeded or failed, and can decide which method to try next or stop the process entirely.

Run it now

Todaygo
// This program demonstrates the current state of the x/crypto/ssh package
// before the AuthCallback feature is available. It constructs a
// ClientAuthContext manually and prints its fields. The AuthCallback
// field does not exist in Go 1.27.1, so we cannot use it here.
// The program compiles and runs with the standard library only.

package main

import (
	"fmt"
)

type ConnMetadata struct{ Host string }
type NegotiatedAlgorithms struct{ KeyAlgo string }

type ClientAuthContext struct {
	Metadata              ConnMetadata
	Algorithms            NegotiatedAlgorithms
	AllowedMethods        []string
	PartialSuccessMethods []string
	TriedMethods          []string
}

func main() {
	// Create a sample context that might be passed to a future AuthCallback.
	ctx := ClientAuthContext{
		Metadata: ConnMetadata{Host: "example.com"},
		Algorithms: NegotiatedAlgorithms{
			KeyAlgo: "curve25519-sha256",
		},
		AllowedMethods:        []string{"publickey", "password"},
		PartialSuccessMethods: []string{"publickey"},
		TriedMethods:          []string{"none"},
	}

	// Print the context to show what information would be available.
	fmt.Printf("Metadata: %+v\n", ctx.Metadata)
	fmt.Printf("Algorithms: %+v\n", ctx.Algorithms)
	fmt.Printf("AllowedMethods: %v\n", ctx.AllowedMethods)
	fmt.Printf("PartialSuccessMethods: %v\n", ctx.PartialSuccessMethods)
	fmt.Printf("TriedMethods: %v\n", ctx.TriedMethods)
}

What it printed when we ran it on Go 1.27.1

Metadata: {Host:example.com}
Algorithms: {KeyAlgo:curve25519-sha256}
AllowedMethods: [publickey password]
PartialSuccessMethods: [publickey]
TriedMethods: [none]

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed