Posted: 11/12/2011 10:12:14
by Matthijs Hoekstra (Basic support level)
Joined: 11/10/2011
Posts: 7

Thanks, I am now able to connect to SSL sites from the phone. The OnCertificateValidate is called and when returning true the data is read. Thanks for the prompt followup.

Next step, figuring out how to validate the certificate.
Posted: 11/12/2011 10:31:43
by Eugene Mayevski (EldoS Corp.)

Until Microsoft opens access to system certificate list (eg. in Silverlight 5 this has happened already) you would have to carry your own list of trusted certificates (that's not hard - you can export trusted certificates from Windows into PFX file and store the PFX in your application resources). Then use TElCertificateValidator and feed it with certificates.

I would say that managing your own list of trusted certificates and CAs is exactly what Firefox does so there's nothing hard or non-standard in this approach. And you can update such list from time to time.

Sincerely yours
Eugene Mayevski
Posted: 11/12/2011 10:37:46
by Matthijs Hoekstra (Basic support level)
Joined: 11/10/2011
Posts: 7

Thanks Eugene, I already suggested this to the productteam so lets see what happens in the next version.

Storing the PFX files and comparing them on the phone would be a good workaround indeed. We need to build in a kill switch in the app to make it stop if the the TOP CA is compromised (really small chance) so the app won't work anymore when the user doesn't update to the latest version. That check can be build with the buildin HTTPRequest object from Mango which does the SSL checks automatically, so I think we can use this for the banking solution.

Working POC, no only to convince the security people next week.

Thanks for the support.
Posted: 12/13/2011 17:00:57
by Kratos Claus (Basic support level)
Joined: 12/13/2011
Posts: 3

There is no example of ssh client for windows phone?
Posted: 12/13/2011 17:51:55
by Ken Ivanov (EldoS Corp.)

Not at the moment, sorry. However, there is an SFTP client sample available (Samples\C#\SFTPBlackbox\Client\WindowsPhone\SimpleSFTPClient\). As TElSimpleSSHClient and TElSimpleSFTPClient share large parts of their interfaces, the sample might be useful for you.
Posted: 04/17/2012 04:10:35
by L haitao (Basic support level)
Joined: 04/17/2012
Posts: 16

how to
ssl socket for wp7.1?
is there a sample ?
Posted: 04/17/2012 04:11:49
by L haitao (Basic support level)
Joined: 04/17/2012
Posts: 16

how to use ssl socket for wp7.1
is there a sample?
Posted: 04/17/2012 04:17:55
by Vsevolod Ievgiienko (EldoS Corp.)

Thank you for contacting us.

You should use TElSimpleSSLClient component. We don't have a sample for WP yet but we have a desktop sample that is located in \EldoS\SecureBlackbox.NET\Samples\C#\SSLBlackbox\Client\SimpleSSLClient folder after SecureBlackbox installation. A major part of code will be the same.
Posted: 04/17/2012 04:48:44
by L haitao (Basic support level)
Joined: 04/17/2012
Posts: 16

but our server is only support socket....
Posted: 04/17/2012 04:54:44
by Vsevolod Ievgiienko (EldoS Corp.)

Could you please clarify your last post.

TElSimpleSSLClient implements exactly what you asked about in the first one: " "ssl socket for wp7.1".
