Zig
Zig
Require SSL Server Certificate Domain Match
See more HTTP Examples
Demonstrates how to require that the SSL server certificate's domain matches the intended domain.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
const http = try chilkat.Http.init();
defer http.deinit();
// Call SetSslCertRequirement to require that the SSL server certificate's domain
// matches only the domain we are intending to communicate with.
// In this example we will test with the URL https://wrong.host.badssl.com/
// which intentionally has an SSL certificate that does not match "wrong.host.badssl.com"
http.setSslCertRequirement("SAN", "wrong.host.badssl.com");
// Also validate the server cert..
http.setRequireSslCertVerify(true);
// Try sending the request. It should fail within the SSL/TLS handshake
// because the server's certificate does not match the domain "wrong.host.badssl.com"
_ = http.quickGetStr(alloc, "https://wrong.host.badssl.com/") catch "";
if (!http.getLastMethodSuccess()) {
std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
} else {
std.debug.print("Unexpected success.\n", .{});
}
}