Sample code for 30+ languages & platforms
Unicode C++

Set the FTP TLS Version and Ciphers

See more FTP Examples

Demonstrates the TLS negotiation properties SslProtocol and SslAllowedCiphers, and reads back the negotiated TlsVersion and TlsCipherSuite after connecting.

Background: SslProtocol sets the allowed (or minimum) TLS version — default lets Chilkat negotiate the best available, while a value like TLS 1.2 or higher enforces a floor for policy compliance. SslAllowedCiphers narrows the offered cipher suites, which most applications should leave at the secure defaults. The read-only TlsVersion and TlsCipherSuite report what was actually agreed, useful for logging and audits.

Chilkat Unicode C++ Downloads

Unicode C++
#include <CkFtp2W.h>

void ChilkatSample(void)
    {
    bool success = false;

    CkFtp2W ftp;

    ftp.put_Hostname(L"ftp.example.com");
    ftp.put_Username(L"myFtpLogin");

    ftp.put_AuthTls(true);

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    ftp.put_Password(L"myPassword");

    //  Require at least TLS 1.2.  Accepted values include "default", "TLS 1.3", "TLS 1.2",
    //  "TLS 1.2 or higher", and so on.  "default" lets Chilkat negotiate the best available.
    ftp.put_SslProtocol(L"TLS 1.2 or higher");

    //  Optionally restrict the cipher suites offered.  Leave empty to use Chilkat's secure defaults.
    ftp.put_SslAllowedCiphers(L"TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256");

    success = ftp.Connect();
    if (success == false) {
        wprintf(L"%s\n",ftp.lastErrorText());
        return;
    }

    //  After connecting, read back what was actually negotiated.
    wprintf(L"Negotiated TLS version: %s\n",ftp.tlsVersion());
    wprintf(L"Negotiated cipher suite: %s\n",ftp.tlsCipherSuite());

    success = ftp.Disconnect();
    if (success == false) {
        wprintf(L"%s\n",ftp.lastErrorText());
        return;
    }
    }