DataFlex
DataFlex
Verify and Pin the FTPS Server Certificate
See more FTP Examples
Demonstrates the certificate-verification properties RequireSslCertVerify, TlsPinSet, and the read-only SslServerCertVerified.
Background: By default a TLS connection is not rejected merely because certificate-chain verification fails, so
RequireSslCertVerify = true is the important hardening step — it makes an expired, unsigned, or untrusted certificate abort the connection. TlsPinSet adds public-key pinning on top: the handshake fails unless the server's SPKI fingerprint matches one you configured, defending against a mis-issued certificate that would otherwise validate. Pinning supplements verification rather than replacing it. SslServerCertVerified reports the outcome.Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
Handle hoFtp
String sTemp1
Boolean bTemp1
Move False To iSuccess
Get Create (RefClass(cComChilkatFtp2)) To hoFtp
If (Not(IsComObjectCreated(hoFtp))) Begin
Send CreateComObject of hoFtp
End
Set ComHostname Of hoFtp To "ftp.example.com"
Set ComUsername Of hoFtp To "myFtpLogin"
Set ComAuthTls Of hoFtp To True
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
Set ComPassword Of hoFtp To "myPassword"
// Reject the connection if the server certificate cannot be verified (expired, bad signature,
// untrusted chain, etc.). The default is False, which does not reject on verification
// failure -- set True for security.
Set ComRequireSslCertVerify Of hoFtp To True
// Optionally pin the server's public key. If none of the configured SPKI fingerprints matches,
// the TLS handshake fails. Pinning supplements normal verification; it does not replace it.
Set ComTlsPinSet Of hoFtp To "sha256//YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="
Get ComConnect Of hoFtp To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoFtp To sTemp1
Showln sTemp1
Procedure_Return
End
// SslServerCertVerified reports whether the certificate chain was successfully verified.
Get ComSslServerCertVerified Of hoFtp To bTemp1
If (bTemp1) Begin
Showln "The server certificate was verified."
End
Get ComDisconnect Of hoFtp To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoFtp To sTemp1
Showln sTemp1
Procedure_Return
End
End_Procedure