Tcl
Tcl
Use a Custom Set of Trusted Root Certificates
See more Certificates Examples
Demonstrates how to build a set of trusted root certificates to be used globally by all Chilkat classes.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
set trustedRoots [new_CkTrustedRoots]
# Indicate that we will NOT trust any pre-installed certificates on the system.
CkTrustedRoots_put_TrustSystemCaRoots $trustedRoots 0
# Thawte is a certificate authority that provides a .zip download of their
# root CA certificates: https://www.thawte.com/roots/index.html
# The direct download link is: https://www.verisign.com/support/thawte-roots.zip
# Note: The above URLs are valid at the time of writing this example (29-May-2015).
# Assuming the .zip has already been downloaded, open it and load each .pem file into
# our trusted roots object.
set zip [new_CkZip]
# Open a .zip containing PEM files, among other things..
set success [CkZip_OpenZip $zip "qa_data/certs/thawte-roots.zip"]
if {$success == 0} then {
puts [CkZip_lastErrorText $zip]
delete_CkTrustedRoots $trustedRoots
delete_CkZip $zip
exit
}
set entry [new_CkZipEntry]
set cert [new_CkCert]
set pattern "*.pem"
set bHasMoreEntries [CkZip_EntryMatching $zip $pattern $entry]
while {$bHasMoreEntries == 1} {
puts "Entry: [CkZipEntry_fileName $entry]"
# Get the PEM of the CA cert:
set pemStr [CkZipEntry_unzipToString $entry 0 "utf-8"]
# Load it into a certificate object:
set success [CkCert_LoadPem $cert $pemStr]
if {$success != 1} then {
puts [CkCert_lastErrorText $cert]
}
# Add it to the trusted roots.
CkTrustedRoots_AddCert $trustedRoots $cert
set bHasMoreEntries [CkZipEntry_GetNextMatch $entry $pattern]
}
# Activate the trusted roots globally for all Chilkat objects.
# This call really shouldn't fail, so we're not checking the return value.
set success [CkTrustedRoots_Activate $trustedRoots]
delete_CkTrustedRoots $trustedRoots
delete_CkZip $zip
delete_CkZipEntry $entry
delete_CkCert $cert