Sample code for 30+ languages & platforms
Zig

Socket TLS Mutual Authentication (Client-Side Certificate)

See more Socket/SSL/TLS Examples

This example demonstrates how to provide a client-side certificate, also known as "two-way authentication" or "mutual authentication" for servers that require a client certificate.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const sock = try chilkat.Socket.init();
    defer sock.deinit();

    // Set the certificate to be used for mutual TLS authentication
    // (i.e. sets the client-side certificate for two-way TLS authentication)
    sock.setSslClientCertPfx("/home/bob/pfxFiles/myClientSideCertWithPrivateKey.pfx", "pfxPassword") catch {
        std.debug.print("{s}\n", .{try sock.getLastErrorText(alloc)});
        return;
    };

    // Note: The certificate used for the client-side of TLS mutual authentication
    // must have the associated private key available. (.pfx/.p12 files typically store both
    // the certificate and associated private key.)

    // Establish the connection using the socket object (with client certificate authentication).
    const b_tls = true;
    const port = 443;
    const max_wait_ms = 5000;
    sock.connect("www.example.com", port, b_tls, max_wait_ms) catch {
        std.debug.print("Connect Failure Error Code: {d}\n", .{sock.getConnectFailReason()});
        std.debug.print("{s}\n", .{try sock.getLastErrorText(alloc)});
        return;
    };

    // At this point, the Socket object is connected and authenticated using the client-side cert

    // ...
    // ...
}