Sample code for 30+ languages & platforms
Xbase++

Set a TLS Client Certificate for IMAP

See more IMAP Examples

Demonstrates the Chilkat Imap.SetSslClientCert method, which supplies a client certificate for TLS client-certificate authentication. The only argument is a Cert object that must provide access to its private key. Call it before connecting. This example loads the certificate from a PFX file.

Note: The certificate path is relative to the application's current working directory. Supply the path to your own certificate file.

Background: Most IMAP servers authenticate with a username and password only. A few high-security deployments additionally require mutual TLS, where the client presents its own certificate during the handshake. Because that happens as part of connecting, the certificate must be set before Connect — setting it afterward has no effect on the already-established connection.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oImap
LOCAL cPfxPassword
LOCAL oCert

nSuccess := 0

//  Demonstrates the Imap.SetSslClientCert method, which supplies a client certificate for TLS
//  client-certificate authentication.  The only argument is a Cert object.  It must be called
//  before connecting.

oImap := CreateObject("Chilkat.Imap")

oImap:Ssl := 1
oImap:Port := 993

//  The PFX password is not hard-coded in source.  Insert code here to obtain it from an
//  interactive prompt, environment variable, or a secrets vault.

//  Load the client certificate (and its private key) from a PFX file.
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadPfxFile("qa_data/client.pfx", cPfxPassword)
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oImap:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Provide the client certificate BEFORE connecting.
nSuccess := oImap:SetSslClientCert(oCert)
IF (nSuccess == 0)
    ? oImap:LastErrorText
    oImap:destroy()
    oCert:destroy()
    RETURN
ENDIF

nSuccess := oImap:Connect("imap.example.com")
IF (nSuccess == 0)
    ? oImap:LastErrorText
    oImap:destroy()
    oCert:destroy()
    RETURN
ENDIF

nSuccess := oImap:Login("user@example.com", "myPassword")
IF (nSuccess == 0)
    ? oImap:LastErrorText
    oImap:destroy()
    oCert:destroy()
    RETURN
ENDIF

nSuccess := oImap:Disconnect()
IF (nSuccess == 0)
    ? oImap:LastErrorText
    oImap:destroy()
    oCert:destroy()
    RETURN
ENDIF

oImap:destroy()
oCert:destroy()