Sample code for 30+ languages & platforms
DataFlex

HTTP - Verify Server is a Trusted Root CA

See more HTTP Examples

Demonstrates how to only allow connections to an HTTP server having a certificate with a root that is in our list of trusted CA root certificates.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    String sUrl
    Handle hoHttp
    String sHtml
    Handle hoTrustedRoots
    String sTemp1
    Boolean bTemp1

    Move False To iSuccess

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    Move False To iSuccess

    //  On my particular system, the root CA cert for this URL is not pre-installed.
    //  Note: This may be different for you.
    //  Also, this example was written on 29-May-2015.  This URL was valid at the time,
    //  but may not be valid at a future date.
    Move "https://animals.nationalgeographic.com/animals/invertebrates/starfish/" To sUrl

    Get Create (RefClass(cComChilkatHttp)) To hoHttp
    If (Not(IsComObjectCreated(hoHttp))) Begin
        Send CreateComObject of hoHttp
    End

    //  Require that the SSL/TLS server certificate is not expired,
    //  and that the certificate signature is valid.
    //  This does not ensure that it has a chain of authentication to
    //  a trusted root.  To ensure that, the TrustedRoots object (below) is required.
    Set ComRequireSslCertVerify Of hoHttp To True

    //  Do the HTTPS page fetch (through the SSH tunnel)
    Get ComQuickGetStr Of hoHttp sUrl To sHtml
    Get ComLastMethodSuccess Of hoHttp To bTemp1
    If (bTemp1 <> True) Begin
        Get ComLastErrorText Of hoHttp To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln "The HTTP GET was successful."

    //  Now let's require that HTTP requests to SSL/TLS servers that don't have trusted CA roots
    //  should fail.
    Get Create (RefClass(cComChilkatTrustedRoots)) To hoTrustedRoots
    If (Not(IsComObjectCreated(hoTrustedRoots))) Begin
        Send CreateComObject of hoTrustedRoots
    End

    //  Indicate that we will trust any pre-installed certificates on this system.
    //  (The meaning of pre-installed certificates depends on the operating system, and in
    //  some environments there is no such thing as pre-installed certificates.  See the reference
    //  documentation for the TrustedRoots class.)
    Set ComTrustSystemCaRoots Of hoTrustedRoots To True

    //  Activate the trusted roots globally for all Chilkat objects.
    //  This call really shouldn't fail, so we're not checking the return value.
    Get ComActivate Of hoTrustedRoots To iSuccess

    //  Given that our previous HTTP GET likely kept the connection open,
    //  make sure that all HTTP connections are closed before re-trying.
    //  Otherwise, we'll simply be re-using the pre-existing connection.
    Get ComCloseAllConnections Of hoHttp To iSuccess

    //  Now let's try fetching the URL again.  It should fail this time because
    //  there is a requirement that the SSL/TLS server certificate must have a trusted root,
    //  and the trusted root for this URL is not installed on my system (but may be different for you..)
    Get ComQuickGetStr Of hoHttp sUrl To sHtml
    Get ComLastMethodSuccess Of hoHttp To bTemp1
    If (bTemp1 <> True) Begin
        Get ComLastErrorText Of hoHttp To sTemp1
        Showln sTemp1
        Showln "Good, the HTTP request failed as expected."
    End
    Else Begin
        Get ComLastErrorText Of hoHttp To sTemp1
        Showln sTemp1
        Showln "Hmmm... we did not fail as expected?"
    End



End_Procedure