DataFlex
DataFlex
HTTP - Verify Server is a Trusted Root CA
See more HTTP Examples
Demonstrates how to only allow connections to an HTTP server having a certificate with a root that is in our list of trusted CA root certificates.Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
String sUrl
Handle hoHttp
String sHtml
Handle hoTrustedRoots
String sTemp1
Boolean bTemp1
Move False To iSuccess
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
Move False To iSuccess
// On my particular system, the root CA cert for this URL is not pre-installed.
// Note: This may be different for you.
// Also, this example was written on 29-May-2015. This URL was valid at the time,
// but may not be valid at a future date.
Move "https://animals.nationalgeographic.com/animals/invertebrates/starfish/" To sUrl
Get Create (RefClass(cComChilkatHttp)) To hoHttp
If (Not(IsComObjectCreated(hoHttp))) Begin
Send CreateComObject of hoHttp
End
// Require that the SSL/TLS server certificate is not expired,
// and that the certificate signature is valid.
// This does not ensure that it has a chain of authentication to
// a trusted root. To ensure that, the TrustedRoots object (below) is required.
Set ComRequireSslCertVerify Of hoHttp To True
// Do the HTTPS page fetch (through the SSH tunnel)
Get ComQuickGetStr Of hoHttp sUrl To sHtml
Get ComLastMethodSuccess Of hoHttp To bTemp1
If (bTemp1 <> True) Begin
Get ComLastErrorText Of hoHttp To sTemp1
Showln sTemp1
Procedure_Return
End
Showln "The HTTP GET was successful."
// Now let's require that HTTP requests to SSL/TLS servers that don't have trusted CA roots
// should fail.
Get Create (RefClass(cComChilkatTrustedRoots)) To hoTrustedRoots
If (Not(IsComObjectCreated(hoTrustedRoots))) Begin
Send CreateComObject of hoTrustedRoots
End
// Indicate that we will trust any pre-installed certificates on this system.
// (The meaning of pre-installed certificates depends on the operating system, and in
// some environments there is no such thing as pre-installed certificates. See the reference
// documentation for the TrustedRoots class.)
Set ComTrustSystemCaRoots Of hoTrustedRoots To True
// Activate the trusted roots globally for all Chilkat objects.
// This call really shouldn't fail, so we're not checking the return value.
Get ComActivate Of hoTrustedRoots To iSuccess
// Given that our previous HTTP GET likely kept the connection open,
// make sure that all HTTP connections are closed before re-trying.
// Otherwise, we'll simply be re-using the pre-existing connection.
Get ComCloseAllConnections Of hoHttp To iSuccess
// Now let's try fetching the URL again. It should fail this time because
// there is a requirement that the SSL/TLS server certificate must have a trusted root,
// and the trusted root for this URL is not installed on my system (but may be different for you..)
Get ComQuickGetStr Of hoHttp sUrl To sHtml
Get ComLastMethodSuccess Of hoHttp To bTemp1
If (bTemp1 <> True) Begin
Get ComLastErrorText Of hoHttp To sTemp1
Showln sTemp1
Showln "Good, the HTTP request failed as expected."
End
Else Begin
Get ComLastErrorText Of hoHttp To sTemp1
Showln sTemp1
Showln "Hmmm... we did not fail as expected?"
End
End_Procedure