You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Delphi 13 FMX+Indy+TaurusTLS证书加载异常问题求助

Delphi 13 32位FMX + Indy + TaurusTLS 证书加载异常问题

在Delphi 13 32位环境下使用FMX框架,结合Indy与TaurusTLS开发项目时,抛出ETaurusTLSLoadingCertError异常,提示信息为“Could not load certificate.”。

相关细节及已排查操作:

  • 证书由win-acme和simple-acme工具生成,已尝试过带密码/无密码的PEM、PFX两种格式
  • FIOGetPassword方法会在异常触发前被调用;重命名证书文件会触发不同的文件异常,说明程序可以正常读取证书文件
  • 当前将TaurusTLS的PublicKey与PrivateKey均设置为同一个PFX文件
  • 已更换过不同版本的TaurusTLS DLL、不同证书文件、调整SSL版本,异常仍未解决

以下是参考TaurusTLS示例编写的基础FMX单元代码:

unit Unit1;

interface

uses
  System.SysUtils, System.Types, System.UITypes, System.Classes, System.Variants,
  FMX.Types, FMX.Controls, FMX.Forms, FMX.Graphics, FMX.Dialogs, IdCTypes,
  TaurusTLSHeaders_types, TaurusTLS_X509, IdServerIOHandler, IdSSL, TaurusTLS,
  IdBaseComponent, IdComponent, IdCustomTCPServer, IdCustomHTTPServer,
  IdHTTPServer, FMX.Controls.Presentation, FMX.StdCtrls, System.IOUtils,
  IdContext;

type
  TForm1 = class(TForm)
    Button1: TButton;
    fHTTP: TIdHTTPServer;
    FIO: TTaurusTLSServerIOHandler;
    procedure Button1Click(Sender: TObject);
    procedure FIOGetPassword(ASender: TObject; var VPassword: string;
      const AIsWrite: Boolean; var VOk: Boolean);
    procedure FIOVerifyError(ASender: TObject; ACertificate: TTaurusTLSX509;
      const AError: TIdC_LONG; const AMsg, ADescr: string; var VOk: Boolean);
    procedure FIOSecurityLevel(ASender: TObject; const AsslSocket: PSSL;
      ACtx: PSSL_CTX; op, bits: TIdC_INT; const ACipherNid: TIdC_INT;
      const ACipher: string; var VAccepted: Boolean);
    procedure fHTTPException(AContext: TIdContext; AException: Exception);
    procedure fHTTPConnect(AContext: TIdContext);
  private
    { Private declarations }
  public
    { Public declarations }
  end;

var
  Form1: TForm1;

implementation

{$R *.fmx}

procedure TForm1.Button1Click(Sender: TObject);
var
  Loaded: Boolean;

begin
  Loaded := TaurusTLS.LoadOpenSSLLibrary;

  FIO.SSLOptions.Mode := sslmServer;
  // FIO.SSLOptions.UseSystemRootCACertificateStore := False;   Does not fix the issue.
  FIO.DefaultCert.PublicKey := TPath.Combine(ExtractFilePath(ParamStr(0)), 'Certificate\pocketgmserverwithpassword.com.pfx');
  FIO.DefaultCert.PrivateKey := TPath.Combine(ExtractFilePath(ParamStr(0)), 'Certificate\pocketgmserverwithpassword.com.pfx');

  if not FileExists(FIO.DefaultCert.PublicKey) or
     not FileExists(FIO.DefaultCert.PublicKey)
    then SHowMessage('Certificate file name is wrong.');

  FHTTP.IOHandler := FIO;
  FHTTP.DefaultPort := 443;

  try

    FHTTP.Active := True;

  except

    On E:ETaurusTLSLoadingCertError do
      ShowMessage('ETaurusTLSLoadingCertError: ' + E.message);

    On E:Exception do
      ShowMessage('General exception: ' + E.message);

  end;
end;


procedure TForm1.fHTTPConnect(AContext: TIdContext);
begin
  ShowMessage('OnConnect called.');
end;


procedure TForm1.fHTTPException(AContext: TIdContext; AException: Exception);
begin
  ShowMessage('HTTP server exception: ' + AException.Message);
end;


procedure TForm1.FIOGetPassword(ASender: TObject; var VPassword: string;
  const AIsWrite: Boolean; var VOk: Boolean);
begin
  VPassword := 'S******';
  VOk := True;
end;


procedure TForm1.FIOSecurityLevel(ASender: TObject; const AsslSocket: PSSL;
  ACtx: PSSL_CTX; op, bits: TIdC_INT; const ACipherNid: TIdC_INT;
  const ACipher: string; var VAccepted: Boolean);
begin
  ShowMessage('SecurtyLevel called');
end;


procedure TForm1.FIOVerifyError(ASender: TObject; ACertificate: TTaurusTLSX509;
  const AError: TIdC_LONG; const AMsg, ADescr: string; var VOk: Boolean);
begin
  ShowMessage('VerifyError called');
end;


end.

证书加载异常提示

内容的提问来源于stack exchange,提问作者Mike at Bookup

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.11 17:43:13