Tcl
Tcl
Configure a Socket for Server-Side TLS
See more Socket/SSL/TLS Examples
Demonstrates Socket.InitSslServer, which configures the object for server-side TLS using a server certificate that has access to its private key, then listens for and accepts a TLS connection.
The file path is relative to the application's current working directory. An absolute path may also be used. Supply the path appropriate to your own environment.
Background. A TLS listener presents the configured server certificate during the handshake. When client certificates are required, acceptable CA distinguished names are added before InitSslServer.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set socket [new_CkSocket]
# The file path is relative to the application's current working directory. An absolute path
# may also be used. Supply the path appropriate to your own environment.
# The PFX password should come from a secure source rather than being hard-coded.
set pfxPassword "myPfxPassword"
set cert [new_CkCert]
set success [CkCert_LoadPfxFile $cert "qa_data/server.pfx" $pfxPassword]
if {$success == 0} then {
puts [CkCert_lastErrorText $cert]
delete_CkSocket $socket
delete_CkCert $cert
exit
}
# Configure this object for server-side TLS using the certificate. The certificate must have
# access to its corresponding private key.
set success [CkSocket_InitSslServer $socket $cert]
if {$success == 0} then {
puts [CkSocket_lastErrorText $socket]
delete_CkSocket $socket
delete_CkCert $cert
exit
}
# Listen for connections. Accepted connections will use TLS.
set success [CkSocket_BindAndListen $socket 5000 25]
if {$success == 0} then {
puts [CkSocket_lastErrorText $socket]
delete_CkSocket $socket
delete_CkCert $cert
exit
}
set connectedSock [new_CkSocket]
set success [CkSocket_AcceptNext $socket 20000 $connectedSock]
if {$success == 0} then {
puts [CkSocket_lastErrorText $socket]
delete_CkSocket $socket
delete_CkCert $cert
delete_CkSocket $connectedSock
exit
}
puts "Accepted a TLS client connection."
delete_CkSocket $socket
delete_CkCert $cert
delete_CkSocket $connectedSock