Sample code for 30+ languages & platforms
Xbase++

Set the FTP TLS Version and Ciphers

See more FTP Examples

Demonstrates the TLS negotiation properties SslProtocol and SslAllowedCiphers, and reads back the negotiated TlsVersion and TlsCipherSuite after connecting.

Background: SslProtocol sets the allowed (or minimum) TLS version — default lets Chilkat negotiate the best available, while a value like TLS 1.2 or higher enforces a floor for policy compliance. SslAllowedCiphers narrows the offered cipher suites, which most applications should leave at the secure defaults. The read-only TlsVersion and TlsCipherSuite report what was actually agreed, useful for logging and audits.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oFtp

nSuccess := 0

oFtp := CreateObject("Chilkat.Ftp2")

oFtp:Hostname := "ftp.example.com"
oFtp:Username := "myFtpLogin"

oFtp:AuthTls := 1

//  Normally you would not hard-code the password in source.  You should instead obtain it
//  from an interactive prompt, environment variable, or a secrets vault.
oFtp:Password := "myPassword"

//  Require at least TLS 1.2.  Accepted values include "default", "TLS 1.3", "TLS 1.2",
//  "TLS 1.2 or higher", and so on.  "default" lets Chilkat negotiate the best available.
oFtp:SslProtocol := "TLS 1.2 or higher"

//  Optionally restrict the cipher suites offered.  Leave empty to use Chilkat's secure defaults.
oFtp:SslAllowedCiphers := "TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256"

nSuccess := oFtp:Connect()
IF (nSuccess == 0)
    ? oFtp:LastErrorText
    oFtp:destroy()
    RETURN
ENDIF

//  After connecting, read back what was actually negotiated.
? "Negotiated TLS version: " + oFtp:TlsVersion
? "Negotiated cipher suite: " + oFtp:TlsCipherSuite

nSuccess := oFtp:Disconnect()
IF (nSuccess == 0)
    ? oFtp:LastErrorText
    oFtp:destroy()
    RETURN
ENDIF

oFtp:destroy()