Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(DataFlex) HTTP - Verify Server is a Trusted Root CADemonstrates how to only allow connections to an HTTP server having a certificate with a root that is in our list of trusted CA root certificates.
Use ChilkatAx-win32.pkg Procedure Test Handle hoChilkatGlob Boolean iSuccess String sUrl Handle hoHttp String sHtml Handle hoTrustedRoots String sTemp1 Boolean bTemp1 // Starting in v9.5.0.49, all Chilkat classes can be unlocked at once at the beginning of a program // by calling UnlockBundle. It requires a Bundle unlock code. Get Create (RefClass(cComChilkatGlobal)) To hoChilkatGlob If (Not(IsComObjectCreated(hoChilkatGlob))) Begin Send CreateComObject of hoChilkatGlob End Get ComUnlockBundle Of hoChilkatGlob "Anything for 30-day trial." To iSuccess If (iSuccess <> True) Begin Get ComLastErrorText Of hoChilkatGlob To sTemp1 Showln sTemp1 Procedure_Return End // On my particular system, the root CA cert for this URL is not pre-installed. // Note: This may be different for you. // Also, this example was written on 29-May-2015. This URL was valid at the time, // but may not be valid at a future date. Move "https://animals.nationalgeographic.com/animals/invertebrates/starfish/" To sUrl Get Create (RefClass(cComChilkatHttp)) To hoHttp If (Not(IsComObjectCreated(hoHttp))) Begin Send CreateComObject of hoHttp End // Require that the SSL/TLS server certificate is not expired, // and that the certificate signature is valid. // This does not ensure that it has a chain of authentication to // a trusted root. To ensure that, the TrustedRoots object (below) is required. Set ComRequireSslCertVerify Of hoHttp To True // Do the HTTPS page fetch (through the SSH tunnel) Get ComQuickGetStr Of hoHttp sUrl To sHtml Get ComLastMethodSuccess Of hoHttp To bTemp1 If (bTemp1 <> True) Begin Get ComLastErrorText Of hoHttp To sTemp1 Showln sTemp1 Procedure_Return End Showln "The HTTP GET was successful." // Now let's require that HTTP requests to SSL/TLS servers that don't have trusted CA roots // should fail. Get Create (RefClass(cComChilkatTrustedRoots)) To hoTrustedRoots If (Not(IsComObjectCreated(hoTrustedRoots))) Begin Send CreateComObject of hoTrustedRoots End // Indicate that we will trust any pre-installed certificates on this system. // (The meaning of pre-installed certificates depends on the operating system, and in // some environments there is no such thing as pre-installed certificates. See the reference // documentation for the TrustedRoots class.) Set ComTrustSystemCaRoots Of hoTrustedRoots To True // Activate the trusted roots globally for all Chilkat objects. // This call really shouldn't fail, so we're not checking the return value. Get ComActivate Of hoTrustedRoots To iSuccess // Given that our previous HTTP GET likely kept the connection open, // make sure that all HTTP connections are closed before re-trying. // Otherwise, we'll simply be re-using the pre-existing connection. Get ComCloseAllConnections Of hoHttp To iSuccess // Now let's try fetching the URL again. It should fail this time because // there is a requirement that the SSL/TLS server certificate must have a trusted root, // and the trusted root for this URL is not installed on my system (but may be different for you..) Get ComQuickGetStr Of hoHttp sUrl To sHtml Get ComLastMethodSuccess Of hoHttp To bTemp1 If (bTemp1 <> True) Begin Get ComLastErrorText Of hoHttp To sTemp1 Showln sTemp1 Showln "Good, the HTTP request failed as expected." End Else Begin Get ComLastErrorText Of hoHttp To sTemp1 Showln sTemp1 Showln "Hmmm... we did not fail as expected?" End End_Procedure |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.