Sample code for 30+ languages & platforms
Tcl

Download and Trust the DigiCert Global Root CA

See more Certificates Examples

Demonstrates how to download a root certificate and trust it.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# In this example, the URLs for the DigiCert root CA certs are available at this web page:
# https://www.digicert.com/digicert-root-certificates.htm

# This example downloads the "DigiCert Global Root G3"
# Valid until: 15/Jan/2038
# Serial #: 05:55:56:BC:F2:5E:A4:35:35:C3:A4:0F:D5:AB:45:72
# Thumbprint: 7E04DE896A3E666D00E687D33FFAD93BE83D349E

set certUrl "https://dl.cacerts.digicert.com/DigiCertGlobalRootG3.crt"

set http [new_CkHttp]

set bdCert [new_CkBinData]

set success [CkHttp_DownloadBd $http $certUrl $bdCert]
if {$success == 0} then {
    puts [CkHttp_lastErrorText $http]
    delete_CkHttp $http
    delete_CkBinData $bdCert
    exit
}

# Load it into a Chilkat cert object.
set cert [new_CkCert]

set success [CkCert_LoadFromBd $cert $bdCert]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkHttp $http
    delete_CkBinData $bdCert
    delete_CkCert $cert
    exit
}

# Examine the common name,serial, and thumbprint:
puts "CN: [CkCert_subjectCN $cert]"
puts "Serial: [CkCert_serialNumber $cert]"
puts "Thumbprint: [CkCert_sha1Thumbprint $cert]"

# Output from the above:
# CN: DigiCert Global Root G3
# Serial: 055556BCF25EA43535C3A40FD5AB4572
# Thumbprint: 7E04DE896A3E666D00E687D33FFAD93BE83D349E

# If desired, the certificate can be saved to a local file so it does not need
# to be downloaded from the website every time.  
set certPath "qa_data/certs/DigiCertGlobalRootG3.crt"
set success [CkBinData_WriteFile $bdCert $certPath]

# To load the cert from a file...
set success [CkCert_LoadFromFile $cert $certPath]

# Do the following to add the cert to the collection of trusted roots
# for this application.  (Note:  The trust is not persisted.  Each time the
# application runs, it should load the cert (from whatever source, whether it is
# a file, a database,etc.) and do the following:
set troots [new_CkTrustedRoots]

CkTrustedRoots_AddCert $troots $cert
CkTrustedRoots_Activate $troots

puts [CkCert_subjectCN $cert] is now trusted for this run of this application.

delete_CkHttp $http
delete_CkBinData $bdCert
delete_CkCert $cert
delete_CkTrustedRoots $troots