Sample code for 30+ languages & platforms
Xbase++

Use Installed Cert on Windows for TLS Client Authentication

See more HTTP Examples

Demonstrates how to use a certificate that has already been installed on a Windows PC for TLS client authentication.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oHttp
LOCAL oCert

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oHttp := CreateObject("Chilkat.Http")

//  On Windows, a pre-installed certificate can be loaded in a number of different ways.
//  This example loads by the common name:
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadByCommonName("My ECA Medium Assurance Identity Certificate")
IF (nSuccess != 1)
    ? oCert:LastErrorText
    oHttp:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Make sure this certificate has a private key available.  
//  It should be a private key such that when the certificate was installed, it was marked as "exportable"
//  so that authorized programs are able to access the private key.
IF (oCert:HasPrivateKey() != 1)
    ? "A private key is needed for TLS client authentication."
    ? "This certificate has no private key."
    oHttp:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Set the certificate to be used for mutual TLS authentication
//  (i.e. sets the client-side certificate for two-way TLS authentication)
nSuccess := oHttp:SetSslClientCert(oCert)
IF (nSuccess != 1)
    ? oHttp:LastErrorText
    oHttp:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  At this point, the HTTP object instance is setup with the client-side cert, and any SSL/TLS
//  connection will automatically use it if the server demands a client-side cert.

oHttp:destroy()
oCert:destroy()