Sample code for 30+ languages & platforms
Zig

Download and Trust the DigiCert Global Root CA

See more Certificates Examples

Demonstrates how to download a root certificate and trust it.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // In this example, the URLs for the DigiCert root CA certs are available at this web page:
    // https://www.digicert.com/digicert-root-certificates.htm

    // This example downloads the "DigiCert Global Root G3"
    // Valid until: 15/Jan/2038
    // Serial #: 05:55:56:BC:F2:5E:A4:35:35:C3:A4:0F:D5:AB:45:72
    // Thumbprint: 7E04DE896A3E666D00E687D33FFAD93BE83D349E

    const cert_url = "https://dl.cacerts.digicert.com/DigiCertGlobalRootG3.crt";

    const http = try chilkat.Http.init();
    defer http.deinit();
    const bd_cert = try chilkat.BinData.init();
    defer bd_cert.deinit();
    http.downloadBd(cert_url, bd_cert) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    // Load it into a Chilkat cert object.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadFromBd(bd_cert) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Examine the common name,serial, and thumbprint:
    std.debug.print("CN: {s}\n", .{try cert.getSubjectCN(alloc)});
    std.debug.print("Serial: {s}\n", .{try cert.getSerialNumber(alloc)});
    std.debug.print("Thumbprint: {s}\n", .{try cert.getSha1Thumbprint(alloc)});

    // Output from the above:
    // CN: DigiCert Global Root G3
    // Serial: 055556BCF25EA43535C3A40FD5AB4572
    // Thumbprint: 7E04DE896A3E666D00E687D33FFAD93BE83D349E

    // If desired, the certificate can be saved to a local file so it does not need
    // to be downloaded from the website every time.
    const cert_path = "qa_data/certs/DigiCertGlobalRootG3.crt";
    try bd_cert.writeFile(cert_path);

    // To load the cert from a file...
    try cert.loadFromFile(cert_path);

    // Do the following to add the cert to the collection of trusted roots
    // for this application.  (Note:  The trust is not persisted.  Each time the
    // application runs, it should load the cert (from whatever source, whether it is
    // a file, a database,etc.) and do the following:
    const troots = try chilkat.TrustedRoots.init();
    defer troots.deinit();

    troots.addCert(cert) catch {};
    troots.activate() catch {};

    std.debug.print("{s} is now trusted for this run of this application.\n", .{try cert.getSubjectCN(alloc)});
}