Sample code for 30+ languages & platforms
Tcl

Set a TLS Client Certificate for IMAP

See more IMAP Examples

Demonstrates the Chilkat Imap.SetSslClientCert method, which supplies a client certificate for TLS client-certificate authentication. The only argument is a Cert object that must provide access to its private key. Call it before connecting. This example loads the certificate from a PFX file.

Note: The certificate path is relative to the application's current working directory. Supply the path to your own certificate file.

Background: Most IMAP servers authenticate with a username and password only. A few high-security deployments additionally require mutual TLS, where the client presents its own certificate during the handshake. Because that happens as part of connecting, the certificate must be set before Connect — setting it afterward has no effect on the already-established connection.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  Demonstrates the Imap.SetSslClientCert method, which supplies a client certificate for TLS
#  client-certificate authentication.  The only argument is a Cert object.  It must be called
#  before connecting.

set imap [new_CkImap]

CkImap_put_Ssl $imap 1
CkImap_put_Port $imap 993

#  The PFX password is not hard-coded in source.  Insert code here to obtain it from an
#  interactive prompt, environment variable, or a secrets vault.

#  Load the client certificate (and its private key) from a PFX file.
set cert [new_CkCert]

set success [CkCert_LoadPfxFile $cert "qa_data/client.pfx" $pfxPassword]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkImap $imap
    delete_CkCert $cert
    exit
}

#  Provide the client certificate BEFORE connecting.
set success [CkImap_SetSslClientCert $imap $cert]
if {$success == 0} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkImap $imap
    delete_CkCert $cert
    exit
}

set success [CkImap_Connect $imap "imap.example.com"]
if {$success == 0} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkImap $imap
    delete_CkCert $cert
    exit
}

set success [CkImap_Login $imap "user@example.com" "myPassword"]
if {$success == 0} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkImap $imap
    delete_CkCert $cert
    exit
}

set success [CkImap_Disconnect $imap]
if {$success == 0} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkImap $imap
    delete_CkCert $cert
    exit
}


delete_CkImap $imap
delete_CkCert $cert