C
C
Set a TLS Client Certificate for IMAP
See more IMAP Examples
Demonstrates the Chilkat Imap.SetSslClientCert method, which supplies a client certificate for TLS client-certificate authentication. The only argument is a Cert object that must provide access to its private key. Call it before connecting. This example loads the certificate from a PFX file.
Note: The certificate path is relative to the application's current working directory. Supply the path to your own certificate file.
Background: Most IMAP servers authenticate with a username and password only. A few high-security deployments additionally require mutual TLS, where the client presents its own certificate during the handshake. Because that happens as part of connecting, the certificate must be set before
Connect — setting it afterward has no effect on the already-established connection.Chilkat C Downloads
#include <C_CkImap.h>
#include <C_CkCert.h>
void ChilkatSample(void)
{
BOOL success;
HCkImap imap;
const char *pfxPassword;
HCkCert cert;
success = FALSE;
// Demonstrates the Imap.SetSslClientCert method, which supplies a client certificate for TLS
// client-certificate authentication. The only argument is a Cert object. It must be called
// before connecting.
imap = CkImap_Create();
CkImap_putSsl(imap,TRUE);
CkImap_putPort(imap,993);
// The PFX password is not hard-coded in source. Insert code here to obtain it from an
// interactive prompt, environment variable, or a secrets vault.
// Load the client certificate (and its private key) from a PFX file.
cert = CkCert_Create();
success = CkCert_LoadPfxFile(cert,"qa_data/client.pfx",pfxPassword);
if (success == FALSE) {
printf("%s\n",CkCert_lastErrorText(cert));
CkImap_Dispose(imap);
CkCert_Dispose(cert);
return;
}
// Provide the client certificate BEFORE connecting.
success = CkImap_SetSslClientCert(imap,cert);
if (success == FALSE) {
printf("%s\n",CkImap_lastErrorText(imap));
CkImap_Dispose(imap);
CkCert_Dispose(cert);
return;
}
success = CkImap_Connect(imap,"imap.example.com");
if (success == FALSE) {
printf("%s\n",CkImap_lastErrorText(imap));
CkImap_Dispose(imap);
CkCert_Dispose(cert);
return;
}
success = CkImap_Login(imap,"user@example.com","myPassword");
if (success == FALSE) {
printf("%s\n",CkImap_lastErrorText(imap));
CkImap_Dispose(imap);
CkCert_Dispose(cert);
return;
}
success = CkImap_Disconnect(imap);
if (success == FALSE) {
printf("%s\n",CkImap_lastErrorText(imap));
CkImap_Dispose(imap);
CkCert_Dispose(cert);
return;
}
CkImap_Dispose(imap);
CkCert_Dispose(cert);
}