Sample code for 30+ languages & platforms
DataFlex

Verify and Pin the FTPS Server Certificate

See more FTP Examples

Demonstrates the certificate-verification properties RequireSslCertVerify, TlsPinSet, and the read-only SslServerCertVerified.

Background: By default a TLS connection is not rejected merely because certificate-chain verification fails, so RequireSslCertVerify = true is the important hardening step — it makes an expired, unsigned, or untrusted certificate abort the connection. TlsPinSet adds public-key pinning on top: the handshake fails unless the server's SPKI fingerprint matches one you configured, defending against a mis-issued certificate that would otherwise validate. Pinning supplements verification rather than replacing it. SslServerCertVerified reports the outcome.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoFtp
    String sTemp1
    Boolean bTemp1

    Move False To iSuccess

    Get Create (RefClass(cComChilkatFtp2)) To hoFtp
    If (Not(IsComObjectCreated(hoFtp))) Begin
        Send CreateComObject of hoFtp
    End

    Set ComHostname Of hoFtp To "ftp.example.com"
    Set ComUsername Of hoFtp To "myFtpLogin"

    Set ComAuthTls Of hoFtp To True

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    Set ComPassword Of hoFtp To "myPassword"

    //  Reject the connection if the server certificate cannot be verified (expired, bad signature,
    //  untrusted chain, etc.).  The default is False, which does not reject on verification
    //  failure -- set True for security.
    Set ComRequireSslCertVerify Of hoFtp To True

    //  Optionally pin the server's public key.  If none of the configured SPKI fingerprints matches,
    //  the TLS handshake fails.  Pinning supplements normal verification; it does not replace it.
    Set ComTlsPinSet Of hoFtp To "sha256//YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="

    Get ComConnect Of hoFtp To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoFtp To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  SslServerCertVerified reports whether the certificate chain was successfully verified.
    Get ComSslServerCertVerified Of hoFtp To bTemp1
    If (bTemp1) Begin
        Showln "The server certificate was verified."
    End

    Get ComDisconnect Of hoFtp To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoFtp To sTemp1
        Showln sTemp1
        Procedure_Return
    End



End_Procedure