Xbase++
Xbase++
Set the FTP TLS Version and Ciphers
See more FTP Examples
Demonstrates the TLS negotiation properties SslProtocol and SslAllowedCiphers, and reads back the negotiated TlsVersion and TlsCipherSuite after connecting.
Background:
SslProtocol sets the allowed (or minimum) TLS version — default lets Chilkat negotiate the best available, while a value like TLS 1.2 or higher enforces a floor for policy compliance. SslAllowedCiphers narrows the offered cipher suites, which most applications should leave at the secure defaults. The read-only TlsVersion and TlsCipherSuite report what was actually agreed, useful for logging and audits.Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oFtp
nSuccess := 0
oFtp := CreateObject("Chilkat.Ftp2")
oFtp:Hostname := "ftp.example.com"
oFtp:Username := "myFtpLogin"
oFtp:AuthTls := 1
// Normally you would not hard-code the password in source. You should instead obtain it
// from an interactive prompt, environment variable, or a secrets vault.
oFtp:Password := "myPassword"
// Require at least TLS 1.2. Accepted values include "default", "TLS 1.3", "TLS 1.2",
// "TLS 1.2 or higher", and so on. "default" lets Chilkat negotiate the best available.
oFtp:SslProtocol := "TLS 1.2 or higher"
// Optionally restrict the cipher suites offered. Leave empty to use Chilkat's secure defaults.
oFtp:SslAllowedCiphers := "TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256"
nSuccess := oFtp:Connect()
IF (nSuccess == 0)
? oFtp:LastErrorText
oFtp:destroy()
RETURN
ENDIF
// After connecting, read back what was actually negotiated.
? "Negotiated TLS version: " + oFtp:TlsVersion
? "Negotiated cipher suite: " + oFtp:TlsCipherSuite
nSuccess := oFtp:Disconnect()
IF (nSuccess == 0)
? oFtp:LastErrorText
oFtp:destroy()
RETURN
ENDIF
oFtp:destroy()