C
C
Use a TLS Client Certificate
See more SMTP Examples
Demonstrates the Chilkat MailMan.SetSslClientCert method, which sets the client-side certificate to use for SSL/TLS connections. This is typically not required — most SSL/TLS connections authenticate the server only. This example loads a client certificate from a PFX and uses it when connecting.
Background: In an ordinary TLS handshake only the server presents a certificate, and the client proves who it is later with a password. Mutual TLS adds a second leg: the client also presents a certificate, so it is authenticated cryptographically at the transport layer. Some corporate or high-security mail servers require this. Because the client must prove possession of the key, the certificate needs its private key — hence loading from a PFX.
Chilkat C Downloads
#include <C_CkMailMan.h>
#include <C_CkCert.h>
void ChilkatSample(void)
{
BOOL success;
HCkMailMan mailman;
HCkCert cert;
success = FALSE;
// Demonstrates the MailMan.SetSslClientCert method, which sets the client-side certificate
// to use for SSL/TLS connections. This is typically not required -- most SSL/TLS
// connections authenticate the server only.
mailman = CkMailMan_Create();
// Configure the SMTP server connection.
CkMailMan_putSmtpHost(mailman,"smtp.example.com");
CkMailMan_putSmtpPort(mailman,465);
CkMailMan_putSmtpSsl(mailman,TRUE);
CkMailMan_putSmtpUsername(mailman,"user@example.com");
CkMailMan_putSmtpPassword(mailman,"myPassword");
// Load the client certificate (with its private key) from a PFX file.
cert = CkCert_Create();
success = CkCert_LoadPfxFile(cert,"qa_data/certs/client.pfx","pfx_password");
if (success == FALSE) {
printf("%s\n",CkCert_lastErrorText(cert));
CkMailMan_Dispose(mailman);
CkCert_Dispose(cert);
return;
}
// Use this certificate to identify the client during the TLS handshake.
success = CkMailMan_SetSslClientCert(mailman,cert);
if (success == FALSE) {
printf("%s\n",CkMailMan_lastErrorText(mailman));
CkMailMan_Dispose(mailman);
CkCert_Dispose(cert);
return;
}
success = CkMailMan_VerifySmtpLogin(mailman);
if (success == FALSE) {
printf("%s\n",CkMailMan_lastErrorText(mailman));
CkMailMan_Dispose(mailman);
CkCert_Dispose(cert);
return;
}
printf("Connected using a TLS client certificate.\n");
// Note: The path "qa_data/certs/client.pfx" is a relative local filesystem path,
// relative to the current working directory of the running application.
CkMailMan_Dispose(mailman);
CkCert_Dispose(cert);
}