Sample code for 30+ languages & platforms
Visual FoxPro

Require Specific FTPS Server Certificate Fields

See more FTP Examples

Demonstrates the Chilkat Ftp2.SetSslCertRequirement method, which adds a required match against the FTP server certificate. The first argument selects the certificate field (such as SubjectCN or IssuerCN) and the second is the required value. It is a void method; a non-matching certificate causes the connection to fail.

Background: Standard TLS validation confirms a certificate is trusted and valid for the hostname, but it does not guarantee you reached the specific server you expect — a form of pinning closes that gap. Requiring a certificate field to match a known value rejects any certificate that does not, defending against a mis-issued or substituted certificate even if it would otherwise pass validation. Multiple requirements can be added, and all must be satisfied.

Chilkat Visual FoxPro Downloads

Visual FoxPro
LOCAL lnSuccess
LOCAL loFtp

lnSuccess = 0

*  Demonstrates the Ftp2.SetSslCertRequirement method, which adds a required match against the FTP
*  server certificate.  The 1st argument selects the certificate field and the 2nd is the required
*  value.  It is a void method.

loFtp = CreateObject('Chilkat.Ftp2')

loFtp.Hostname = "ftp.example.com"
loFtp.Username = "myFtpLogin"

*  Normally you would not hard-code the password in source.  You should instead obtain it
*  from an interactive prompt, environment variable, or a secrets vault.
loFtp.Password = "myPassword"

*  Use explicit FTPS (AUTH TLS) on the standard FTP port.
loFtp.AuthTls = 1

*  Require that the server certificate's subject common name matches an expected value.  If the
*  presented certificate does not match, the TLS connection fails.  Supported fields include
*  SubjectDN, SubjectCN, IssuerDN, IssuerCN, and others.
loFtp.SetSslCertRequirement("SubjectCN","ftp.example.com")

lnSuccess = loFtp.Connect()
IF (lnSuccess = 0) THEN
    ? loFtp.LastErrorText
    RELEASE loFtp
    CANCEL
ENDIF

? "Connected; server certificate met the requirement."

lnSuccess = loFtp.Disconnect()
IF (lnSuccess = 0) THEN
    ? loFtp.LastErrorText
    RELEASE loFtp
    CANCEL
ENDIF

RELEASE loFtp