Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Use a Custom Set of Trusted Root Certificates

See more Certificates Examples

Demonstrates how to build a set of trusted root certificates to be used globally by all Chilkat classes.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oTrustedRoots
LOCAL oZip
LOCAL oEntry
LOCAL cPemStr
LOCAL oCert
LOCAL cPattern
LOCAL nBHasMoreEntries

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oTrustedRoots := CreateObject("Chilkat.TrustedRoots")

//   Indicate that we will NOT trust any pre-installed certificates on the system.
oTrustedRoots:TrustSystemCaRoots := 0

//  Thawte is a certificate authority that provides a .zip download of their
//  root CA certificates:  https://www.thawte.com/roots/index.html
//  The direct download link is: https://www.verisign.com/support/thawte-roots.zip
//  Note: The above URLs are valid at the time of writing this example (29-May-2015).

//  Assuming the .zip has already been downloaded, open it and load each .pem file into
//  our trusted roots object.
oZip := CreateObject("Chilkat.Zip")

//  Open a .zip containing PEM files, among other things..
nSuccess := oZip:OpenZip("qa_data/certs/thawte-roots.zip")
IF (nSuccess == 0)
    ? oZip:LastErrorText
    oTrustedRoots:destroy()
    oZip:destroy()
    RETURN
ENDIF

oEntry := CreateObject("Chilkat.ZipEntry")

oCert := CreateObject("Chilkat.Cert")

cPattern := "*.pem"
nBHasMoreEntries := oZip:EntryMatching(cPattern, oEntry)
DO WHILE nBHasMoreEntries == 1

    ? "Entry: " + oEntry:FileName

    //  Get the PEM of the CA cert:
    cPemStr := oEntry:UnzipToString(0, "utf-8")

    //  Load it into a certificate object:
    nSuccess := oCert:LoadPem(cPemStr)
    IF (nSuccess != 1)
        ? oCert:LastErrorText
    ENDIF

    //  Add it to the trusted roots.
    oTrustedRoots:AddCert(oCert)

    nBHasMoreEntries := oEntry:GetNextMatch(cPattern)
ENDDO

//   Activate the trusted roots globally for all Chilkat objects.
//   This call really shouldn't fail, so we're not checking the return value.
nSuccess := oTrustedRoots:Activate()

oTrustedRoots:destroy()
oZip:destroy()
oEntry:destroy()
oCert:destroy()