# OFTPClient Component

The OFTPClient component implements the Odette File Transfer Protocol.

## Syntax

```text
nsoftware.IPWorksEDI.OFTPClient
```

## Remarks

The OFTPClient component may be used to send and receive OFTP files to and from an OFTP server.

**Receiving Files**

 The OFTPClient [ReceiveFiles](#receivefiles-method-oftpclient-component) function requires certain server properties be set. You must set the [RemoteHost](#remotehost-property-oftpclient-component) property to the remote location of the desired OFTP server. You may also set a [RemotePort](#remoteport-property-oftpclient-component) if the server is not set to the default protocol port. For client authorization, you must set the [ClientSSIDCode](#clientssidcode-property-oftpclient-component), [ClientSFIDCode](#clientsfidcode-property-oftpclient-component), and [ClientPassword](#clientpassword-property-oftpclient-component) properties. And, for server authentication, you must set the [ServerSSIDCode](#serverssidcode-property-oftpclient-component), [ServerSFIDCode](#serversfidcode-property-oftpclient-component), and [ServerPassword](#serverpassword-property-oftpclient-component) properties.

The component will connect to the OFTP server and download all files in the server's outgoing queue, and write these files to the directory specified by [DownloadDirectory](#downloaddirectory-property-oftpclient-component). The component creates a default location on the local machine based on the values of the [DownloadDirectory](#downloaddirectory-property-oftpclient-component) and the Virtual Filename as received from the server. If a different location is preferred, you may set the **LocalFile** parameter of the [StartTransfer](#starttransfer-event-oftpclient-component) event.

**Sending Files**

 The OFTPClient [SendFile](#sendfile-method-oftpclient-component) function requires the same server and authentication properties to be set as the [ReceiveFiles](#receivefiles-method-oftpclient-component) function.

The component will connect to the OFTP server and upload the file contained by the **LocalFile** parameter. It uses the name specified by **VirtualFileName** when sending to the server. If this is not specified, the filename of the local file is parsed and used as the virtual filename.

## Property List

*The following is the full list of the properties of the component with short descriptions. Click on the links for further details.*

|  |  |
| --- | --- |
| [Certificate](#certificate-property-oftpclient-component) | The current selected certificate. |
| [ClientPassword](#clientpassword-property-oftpclient-component) | The client's password. |
| [ClientSFIDCode](#clientsfidcode-property-oftpclient-component) | Client's SFID code. |
| [ClientSSIDCode](#clientssidcode-property-oftpclient-component) | The client's SSID code. |
| [Compress](#compress-property-oftpclient-component) | Whether or not to compress the outgoing file. |
| [Connected](#connected-property-oftpclient-component) | Shows whether the component is connected. |
| [DownloadDirectory](#downloaddirectory-property-oftpclient-component) | Download directory. |
| [EncryptionAlgorithm](#encryptionalgorithm-property-oftpclient-component) | The encryption algorithm. |
| [Firewall](#firewall-property-oftpclient-component) | A set of properties related to firewall access. |
| [LocalHost](#localhost-property-oftpclient-component) | The name of the local host or user-assigned IP interface through which connections are initiated or accepted. |
| [MaxRecordSize](#maxrecordsize-property-oftpclient-component) | The maximum length of a given record. |
| [Overwrite](#overwrite-property-oftpclient-component) | Whether or not the component should overwrite files during transfer. |
| [RecipientCert](#recipientcert-property-oftpclient-component) | The recipient certificate of the message. |
| [RemoteHost](#remotehost-property-oftpclient-component) | The domain name or IP address of the OFTP server. |
| [RemotePort](#remoteport-property-oftpclient-component) | The port for the OFTP service (default is 3305). |
| [SecureAuthentication](#secureauthentication-property-oftpclient-component) | Whether or not the component should perform secure Odette authentication. |
| [ServerPassword](#serverpassword-property-oftpclient-component) | The server's password. |
| [ServerSFIDCode](#serversfidcode-property-oftpclient-component) | Server's SFID code. |
| [ServerSSIDCode](#serverssidcode-property-oftpclient-component) | The server's SSID code. |
| [SignedReceipt](#signedreceipt-property-oftpclient-component) | Whether or not to require signed receipts. |
| [SSLAcceptServerCert](#sslacceptservercert-property-oftpclient-component) | Instructs the component to unconditionally accept the server certificate that matches the supplied certificate. |
| [SSLCert](#sslcert-property-oftpclient-component) | The certificate to be used during Secure Sockets Layer (SSL) negotiation. |
| [Timeout](#timeout-property-oftpclient-component) | This property includes the timeout for the component. |
| [TrustedCerts](#trustedcerts-property-oftpclient-component) | A collection of trusted CA certificates. |
| [UseSSL](#usessl-property-oftpclient-component) | Use SSL to access the [RemoteHost](#remotehost-property-oftpclient-component) . |
| [Version](#version-property-oftpclient-component) | Which version of the OFTP protocol the component is using. |
| [VirtualFileDate](#virtualfiledate-property-oftpclient-component) | The date/time stamp for the virtual file. |
| [VirtualFileFormat](#virtualfileformat-property-oftpclient-component) | The structure of the outgoing file. |
| [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) | The level of security for the file. |

## Method List

*The following is the full list of the methods of the component with short descriptions. Click on the links for further details.*

|  |  |
| --- | --- |
| [ChangeDirection](#changedirection-method-oftpclient-component) | Sends a Change Direction (CD) command. |
| [Config](#config-method-oftpclient-component) | Sets or retrieves a configuration setting. |
| [Connect](#connect-method-oftpclient-component) | This method connects to the FTP server without logging in. |
| [Disconnect](#disconnect-method-oftpclient-component) | This method disconnects from the server without first logging off. |
| [DoEvents](#doevents-method-oftpclient-component) | This method processes events from the internal message queue. |
| [ExchangeCertificate](#exchangecertificate-method-oftpclient-component) | Exchange a certificate with the remote host. |
| [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) | Imports a list of trusted CA certificates. |
| [Interrupt](#interrupt-method-oftpclient-component) | This method interrupts the current action. |
| [Logoff](#logoff-method-oftpclient-component) | Logoff from the OFTP server. |
| [Logon](#logon-method-oftpclient-component) | Logon to the OFTP [RemoteHost](#remotehost-property-oftpclient-component) using the current client credentials. |
| [ReceiveFiles](#receivefiles-method-oftpclient-component) | Receive any files queued to be sent from the server. |
| [Reset](#reset-method-oftpclient-component) | Resets the state of the control. |
| [SendEndResponse](#sendendresponse-method-oftpclient-component) | Sends an EERP/NERP asynchronously. |
| [SendFile](#sendfile-method-oftpclient-component) | Send the specified file to the server. |
| [SetDownloadStream](#setdownloadstream-method-oftpclient-component) | Sets the stream to which the downloaded file is written. |
| [SetUploadStream](#setuploadstream-method-oftpclient-component) | Sets the stream to be uploaded to the server. |
| [ValidateCert](#validatecert-method-oftpclient-component) | Validates the certificate with private key. |
| [ValidateRecipientCert](#validaterecipientcert-method-oftpclient-component) | Validates the recipient certificate. |

## Event List

*The following is the full list of the events fired by the component with short descriptions. Click on the links for further details.*

|  |  |
| --- | --- |
| [AcceptFile](#acceptfile-event-oftpclient-component) | Fired when the client receives a file. |
| [CertificateReceived](#certificatereceived-event-oftpclient-component) | Fired when a certificate is received from the remote host. |
| [EndResponse](#endresponse-event-oftpclient-component) | Fired every time an end response is received from the server. |
| [EndTransfer](#endtransfer-event-oftpclient-component) | Fired when a file finishes transferring. |
| [Error](#error-event-oftpclient-component) | Fired when information is available about errors during data delivery. |
| [Log](#log-event-oftpclient-component) | Fires once for each log message. |
| [PITrail](#pitrail-event-oftpclient-component) | Fired when any protocol level communication occurs. |
| [SSLServerAuthentication](#sslserverauthentication-event-oftpclient-component) | Fired after the server presents its certificate to the client. |
| [SSLStatus](#sslstatus-event-oftpclient-component) | Fired when secure connection progress messages are available. |
| [StartTransfer](#starttransfer-event-oftpclient-component) | Fired when a document starts transferring. |
| [Transfer](#transfer-event-oftpclient-component) | Fired while a document transfers (delivers document). |

## Config Settings

*The following is a list of config settings for the component with short descriptions. Click on the links for further details.*

|  |  |
| --- | --- |
| [AcceptAnySFIDCode](#AcceptAnySFIDCode) | Indicates that all SFID codes are acceptable. |
| [AllowRetry](#AllowRetry) | Whether to send a retry indicator when rejecting a file. |
| [CertificateType](#CertificateType) | Specifies the type of certificate being supplied. |
| [ConnectionType](#ConnectionType) | Specifies the type of connection that will be created. |
| [CreditCount](#CreditCount) | Specifies the credit value. |
| [DeleteOnError](#DeleteOnError) | Whether received files are deleted when there is an error during processing. |
| [DisconnectAfterEndSession](#DisconnectAfterEndSession) | Determines if the connection is closed immediately after ending the session. |
| [EnforceProtocolVersion](#EnforceProtocolVersion) | Requires the server to support the same OFTP version. |
| [ExchangeBufferSize](#ExchangeBufferSize) | Specifies the data exchange buffer size in bytes. |
| [ExchangeCertStoreType](#ExchangeCertStoreType) | Specifies the store type when loading a certificate to be exchanged. |
| [ExchangeCertSubject](#ExchangeCertSubject) | The subject of the certificate being exchanged. |
| [FailOnUntrustedCert](#FailOnUntrustedCert) | Whether or not to throw an exception when untrusted certificates are used. |
| [FileDescription](#FileDescription) | Additional description information sent with the file. |
| [FileHashAlgorithm](#FileHashAlgorithm) | The hash algorithm to use when sending a file. |
| [FireEndResponseOnSend](#FireEndResponseOnSend) | Determines if the EndResponse event is fired for outgoing EERP and NERPs. |
| [FollowRedirects](#FollowRedirects) | Determines behavior when importing trusted certificates and a HTTP redirect is returned. |
| [FriendlyLogFormat](#FriendlyLogFormat) | Determines if a more friendly format is applied to PITrail event out. |
| [LogLevel](#LogLevel) | The level of information to log. |
| [MaskSensitiveData](#MaskSensitiveData) | Masks passwords in logs. |
| [ReceiptHashAlgorithm](#ReceiptHashAlgorithm) | The receipt hash algorithm to request when sending a file. |
| [ReceivedFileDateTime](#ReceivedFileDateTime) | The datetime of the file being received. |
| [ReceivedFileDescription](#ReceivedFileDescription) | Additional description information received with the file. |
| [ReceivedFileEncryptionAlg](#ReceivedFileEncryptionAlg) | The encryption algorithm used for the file being received. |
| [ReceivedFileName](#ReceivedFileName) | Returns the name of the received file. |
| [ReceivedFileNameFormat](#ReceivedFileNameFormat) | The name format of received files. |
| [ReceivedFileNameFormat](#ReceivedFileNameFormat) | The name format of received files. |
| [RecipientCertificateType](#RecipientCertificateType) | Specifies the type of recipient certificate being supplied. |
| [Retry](#Retry) | Indicates whether the recipient allows the send to be retried. |
| [SendCDAfterEFPA](#SendCDAfterEFPA) | Specifies whether a CD is always sent after receiving an EFPA. |
| [TempPath](#TempPath) | The path of a directory where temporary files will be created. |
| [TrustedCertsData](#TrustedCertsData) | Specifies the source to be used when importing trusted certificates. |
| [VirtualFileDateFormat](#VirtualFileDateFormat) | The DateTime format of received files. |
| [BuildInfo](#BuildInfo) | Information about the product's build. |
| [GUIAvailable](#GUIAvailable) | Whether or not a message loop is available for processing events. |
| [LicenseInfo](#LicenseInfo) | Information about the current license. |
| [MaskSensitiveData](#MaskSensitiveData) | Whether sensitive data is masked in log messages. |
| [UseFIPSCompliantAPI](#UseFIPSCompliantAPI) | Tells the component whether or not to use FIPS certified APIs. |
| [UseInternalSecurityAPI](#UseInternalSecurityAPI) | Whether or not to use the system security libraries or an internal implementation. |

# Certificate Property ([OFTPClient](#oftpclient-component) Component)

The current selected certificate.

## Syntax

```text
public Certificate Certificate { get; set; }
```

## Remarks

This property is populated when a specified certificate is found or loaded by the component. Certificate is used for specifying private keys. Set this property to a valid [Certificate](#certificate-type) object to perform different operations such as session authentication, signing a file or receipt, or decryption. To set a certificate, you may set the [Encoded](#Certificate_f_Encoded) field to the encoded certificate. To select a certificate, use the [Store](#Certificate_f_Store) and [Subject](#Certificate_f_Subject) fields.

 Please refer to the [Certificate](#certificate-type) type for a complete list of fields.

# ClientPassword Property ([OFTPClient](#oftpclient-component) Component)

The client's password.

## Syntax

```text
public string ClientPassword { get; set; }
```

## Default Value

""

## Remarks

The password assigned to the client in the bilateral agreement. This property must be a string of no more than 8 characters long.

# ClientSFIDCode Property ([OFTPClient](#oftpclient-component) Component)

Client's SFID code.

## Syntax

```text
public string ClientSFIDCode { get; set; }
```

## Default Value

""

## Remarks

The SFID code identifies the origin or destination party that is sending or receiving a file, while the SSID code identifies the party that a session is established with. If the SFID and SSID codes do not match, then the party the session is established with is acting as an intermediary, and the party identified by the SFID code is either the origin or final destination.

When acting as an intermediary the component will not perform any security services (i.e. sign, verify, encrypt, decrypt). Security services are to be performed by the origin or destination only. Data should simply be passed along by an intermediary.

# ClientSSIDCode Property ([OFTPClient](#oftpclient-component) Component)

The client's SSID code.

## Syntax

```text
public string ClientSSIDCode { get; set; }
```

## Default Value

""

## Remarks

The identification code of the client. This code may be less than, but no more than 25 characters long. Generally, SSID codes have the following format as specified in RFC 2204 that is based on ISO 6523:

|  |  |
| --- | --- |
| Code Identifier | 'O' - Indicates ODETTE assigned the Organization Identifier. Other values can be used for non-ODETTE codes. NOTE: This field is a fixed length of 1 character. |
| International Code | A code forming part of the Organization Identifier. NOTE: This field may be of variable length up to 4 characters long. |
| Organization Code | A code forming part of the Organization Identifier. This field may contain the letters A to Z, the digits 0 to 9, and space and hyphen characters. NOTE: This field may be of variable length up to 14 characters long. |
| Computer Sub-Address | A locally assigned address which uniquely identifies a system within an organization (defined by an Organization Identifier). NOTE: This field may be of variable length up to 6 characters long. |

# Compress Property ([OFTPClient](#oftpclient-component) Component)

Whether or not to compress the outgoing file.

## Syntax

```text
public bool Compress { get; set; }
```

## Default Value

False

## Remarks

When sending a file to the trading partner, set this to true for the component to compress the file before sending. The file will first be compressed to a temporary file before being sent.

Note that this is only applicable when Version 2.0 of the protocol is used as indicated by [Version](#version-property-oftpclient-component).

This property is not available at design time.

# Connected Property ([OFTPClient](#oftpclient-component) Component)

Shows whether the component is connected.

## Syntax

```text
public bool Connected { get; }
```

## Default Value

False

## Remarks

Use this property to determine whether the component is connected to the remote host or not.

Use the [Connect](#connect-method-oftpclient-component) and [Disconnect](#disconnect-method-oftpclient-component) methods to manage the connection.

This property is read-only and not available at design time.

# DownloadDirectory Property ([OFTPClient](#oftpclient-component) Component)

Download directory.

## Syntax

```text
public string DownloadDirectory { get; set; }
```

## Default Value

"./"

## Remarks

This property contains the location on disk of the folder the component will write received files to. The default for this property is "./", which is the current working directory.

Note: If this property is set to empty string data will not be written to disk and instead will be available through the [Transfer](#transfer-event-oftpclient-component) event.

# EncryptionAlgorithm Property ([OFTPClient](#oftpclient-component) Component)

The encryption algorithm.

## Syntax

```text
public OFTPClientEncryptionAlgorithms EncryptionAlgorithm { get; set; }
enum OFTPClientEncryptionAlgorithms {
  encra3DES,
  encraAES
}
```

## Default Value

0

## Remarks

In order to use encryption, you must set the [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) property. The supported algorithms for encryption are:

|  |  |
| --- | --- |
| 3DES (0) | Triple Data Encryption Standard. |
| AES (1) | Advanced Encryption Standard CBC mode with a 256-bit key. |

This property is not available at design time.

# Firewall Property ([OFTPClient](#oftpclient-component) Component)

A set of properties related to firewall access.

## Syntax

```text
public Firewall Firewall { get; set; }
```

## Remarks

This is a [Firewall](#firewall-type)-type property, which contains fields describing the firewall through which the component will attempt to connect.

 Please refer to the [Firewall](#firewall-type) type for a complete list of fields.

# LocalHost Property ([OFTPClient](#oftpclient-component) Component)

The name of the local host or user-assigned IP interface through which connections are initiated or accepted.

## Syntax

```text
public string LocalHost { get; set; }
```

## Default Value

""

## Remarks

This property contains the name of the local host as obtained by the *gethostname()* system call, or if the user has assigned an IP address, the value of that address.

In multihomed hosts (machines with more than one IP interface) setting LocalHost to the IP address of an interface will make the component initiate connections (or accept in the case of server components) only through that interface. It is recommended to provide an IP address rather than a hostname when setting this property to ensure the desired interface is used.

If the component is connected, the LocalHost property shows the IP address of the interface through which the connection is made in internet dotted format (aaa.bbb.ccc.ddd). In most cases, this is the address of the local host, except for multihomed hosts (machines with more than one IP interface).

NOTE: LocalHost is not persistent. You must always set it in code, and never in the property window.

# MaxRecordSize Property ([OFTPClient](#oftpclient-component) Component)

The maximum length of a given record.

## Syntax

```text
public int MaxRecordSize { get; set; }
```

## Default Value

0

## Remarks

This value determines the maximum length for a record in the outgoing virtual file. When [VirtualFileFormat](#virtualfileformat-property-oftpclient-component) has been set to *ffUnstructured* or *ffText*, this value must be zero. When *ffFixed* or *ffVariable*, this must be set to a value greater than 0, containing the maximum line length of the outgoing file.

# Overwrite Property ([OFTPClient](#oftpclient-component) Component)

Whether or not the component should overwrite files during transfer.

## Syntax

```text
public bool Overwrite { get; set; }
```

## Default Value

False

## Remarks

This property is a value indicating whether or not the component should overwrite downloaded files. If Overwrite is false, an error will be thrown whenever the local file exists before a receive operation.

# RecipientCert Property ([OFTPClient](#oftpclient-component) Component)

The recipient certificate of the message.

## Syntax

```text
public Certificate RecipientCert { get; set; }
```

## Remarks

This property specifies the certificate to use when verifying signed files and receipts as well as encrypting files to be sent. This property must be set when [SecureAuthentication](#secureauthentication-property-oftpclient-component) has been set to true, sending a file and [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) has been set to *slEncrypted* or *slEncryptedAndSigned*, [SignedReceipt](#signedreceipt-property-oftpclient-component) has been set to true, or a signed file is being received and the server has not included the certificate in the signature.

The RecipientCert property must be filled out with a valid public key [Certificate](#certificate-type) type object. To set a certificate, you may set the [Encoded](#Certificate_f_Encoded) field to the encoded certificate. To select a certificate, use the [Store](#Certificate_f_Store) and [Subject](#Certificate_f_Subject) fields.

This property is not available at design time.

 Please refer to the [Certificate](#certificate-type) type for a complete list of fields.

# RemoteHost Property ([OFTPClient](#oftpclient-component) Component)

The domain name or IP address of the OFTP server.

## Syntax

```text
public string RemoteHost { get; set; }
```

## Default Value

""

## Remarks

The RemoteHost property specifies the IP address (IP number in dotted internet format) or Domain Name of the OFTP server. It is set before a connection is attempted and cannot be changed once a connection is in progress.

If the RemoteHost property is set to a Domain Name, a DNS request is initiated and upon successful termination of the request, the RemoteHost property is set to the corresponding address. If the search is not successful, an error is returned.

If the component is configured to use a *SOCKS* firewall, the value assigned to this property may be preceded with an "*". If this is the case, the host name is passed to the firewall unresolved and the firewall performs the DNS resolution.

# RemotePort Property ([OFTPClient](#oftpclient-component) Component)

The port for the OFTP service (default is 3305).

## Syntax

```text
public int RemotePort { get; set; }
```

## Default Value

3305

## Remarks

A valid port number (a value between 1 and 65535) is required for the connection to take place. The property must be set before a connection is attempted and cannot be changed once a connection is established. Any attempt to change this property while connected will fail with an error.

When [UseSSL](#usessl-property-oftpclient-component) is set to True this property will be set to 6619.

This property is not available at design time.

# SecureAuthentication Property ([OFTPClient](#oftpclient-component) Component)

Whether or not the component should perform secure Odette authentication.

## Syntax

```text
public bool SecureAuthentication { get; set; }
```

## Default Value

False

## Remarks

If true, the component will perform secure authentication when connecting to the server. The secure authentication consists of encrypting and decrypting data sent to and from the server, and verifying that this occurred successfully. Secure authentication may be performed in plaintext or SSL mode.

Both [Certificate](#certificate-property-oftpclient-component) and [RecipientCert](#recipientcert-property-oftpclient-component) properties must be populated when this property is set to true.

This is only valid for version 2.0 of the protocol.

This property is not available at design time.

# ServerPassword Property ([OFTPClient](#oftpclient-component) Component)

The server's password.

## Syntax

```text
public string ServerPassword { get; set; }
```

## Default Value

""

## Remarks

The password assigned to the server in the bilateral agreement. This property must be a string of no more than 8 characters long.

# ServerSFIDCode Property ([OFTPClient](#oftpclient-component) Component)

Server's SFID code.

## Syntax

```text
public string ServerSFIDCode { get; set; }
```

## Default Value

""

## Remarks

The SFID code identifies the origin or destination party that is sending or receiving a file, while the SSID code identifies the party that a session is established with. If the SFID and SSID codes do not match, then the party the session is established with is acting as an intermediary, and the party identified by the SFID code is either the origin or final destination.

When acting as an intermediary the component will not perform any security services (i.e. sign, verify, encrypt, decrypt). Security services are to be performed by the origin or destination only. Data should simply be passed along by an intermediary.

# ServerSSIDCode Property ([OFTPClient](#oftpclient-component) Component)

The server's SSID code.

## Syntax

```text
public string ServerSSIDCode { get; set; }
```

## Default Value

""

## Remarks

The identification code of the server. This code may be less than, but no more than 25 characters long. Generally, SSID codes have the following format as specified in RFC 2204 that is based on ISO 6523:

|  |  |
| --- | --- |
| Code Identifier | 'O' - Indicates ODETTE assigned the Organization Identifier. Other values can be used for non-ODETTE codes. NOTE: This field is a fixed length of 1 character. |
| International Code | A code forming part of the Organization Identifier. NOTE: This field may be of variable length up to 4 characters long. |
| Organization Code | A code forming part of the Organization Identifier. This field may contain the letters A to Z, the digits 0 to 9, and space and hyphen characters. NOTE: This field may be of variable length up to 14 characters long. |
| Computer Sub-Address | A locally assigned address which uniquely identifies a system within an organization (defined by an Organization Identifier). NOTE: This field may be of variable length up to 6 characters long. |

# SignedReceipt Property ([OFTPClient](#oftpclient-component) Component)

Whether or not to require signed receipts.

## Syntax

```text
public bool SignedReceipt { get; set; }
```

## Default Value

False

## Remarks

When sending a file to a trading partner, set this to true if the file receipt should be signed by the server. When this receipt is received by the component, it will be verified during processing.

NOTE: If the server does not attach the public certificate in the signed message, the server's public key must be specified in the [RecipientCert](#recipientcert-property-oftpclient-component) property in order for verification to succeed.

This property is not available at design time.

# SSLAcceptServerCert Property ([OFTPClient](#oftpclient-component) Component)

Instructs the component to unconditionally accept the server certificate that matches the supplied certificate.

## Syntax

```text
public Certificate SSLAcceptServerCert { get; set; }
```

## Remarks

If it finds any issues with the certificate presented by the server, the component will normally terminate the connection with an error.

You may override this behavior by supplying a value for SSLAcceptServerCert. If the certificate supplied in SSLAcceptServerCert is the same as the certificate presented by the server, then the server certificate is accepted unconditionally, and the connection will continue normally.

NOTE: This functionality is provided only for cases in which you otherwise know that you are communicating with the right server. If used improperly, this property may create a security breach. Use it at your own risk.

 Please refer to the [Certificate](#certificate-type) type for a complete list of fields.

# SSLCert Property ([OFTPClient](#oftpclient-component) Component)

The certificate to be used during Secure Sockets Layer (SSL) negotiation.

## Syntax

```text
public Certificate SSLCert { get; set; }
```

## Remarks

This property includes the digital certificate that the component will use during SSL negotiation. Set this property to a valid certificate before starting SSL negotiation. To set a certificate, you may set the [Encoded](#Certificate_f_Encoded) field to the encoded certificate. To select a certificate, use the store and subject fields.

 Please refer to the [Certificate](#certificate-type) type for a complete list of fields.

# Timeout Property ([OFTPClient](#oftpclient-component) Component)

This property includes the timeout for the component.

## Syntax

```text
public int Timeout { get; set; }
```

## Default Value

60

## Remarks

This property defines the timeout when sending data. When SSLEnabled is False a value of 0 means data will be sent asynchronously and a positive value means data is sent synchronously. When SSLEnabled is True all data is sent synchronously regardless of the Timeout value. Please see the notes below for details.

**Plaintext**

If the Timeout property is set to 0, all operations return immediately, potentially failing with a *WOULDBLOCK* error if data cannot be sent immediately.

If Timeout is set to a positive value, data is sent in a blocking manner and the component will wait for the operation to complete before returning control. The component will handle any potential *WOULDBLOCK* errors internally and automatically retry the operation for a maximum of Timeout seconds.

**SSL**

If the Timeout property is set to 0, all operations will run uninterrupted until successful completion or an error condition is encountered.

If Timeout is set to a positive value, the component will wait for the operation to complete before returning control.

**Additional Notes**

The component will use [DoEvents](#doevents-method-oftpclient-component) to enter an efficient wait loop during any potential waiting period, making sure that all system events are processed immediately as they arrive. This ensures that the host application does not freeze and remains responsive.

If Timeout expires, and the operation is not yet complete, the component throws an exception.

NOTE: By default, all timeouts are *inactivity timeouts*, that is, the timeout period is extended by Timeout seconds when any amount of data is successfully sent or received.

The default value for the Timeout property is 60 seconds.

# TrustedCerts Property ([OFTPClient](#oftpclient-component) Component)

A collection of trusted CA certificates.

## Syntax

```text
public CertificateList TrustedCerts { get; }
```

## Remarks

If this collection is populated the component will validate any certificates that are loaded against the CA certificates specified here.

If this collection is not populated no validation will occur. Certificates are imported into this collection by calling the [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) method.

See also [FailOnUntrustedCert](#FailOnUntrustedCert) and [TrustedCertsData](#TrustedCertsData).

This property is not available at design time.

 Please refer to the [Certificate](#certificate-type) type for a complete list of fields.

# UseSSL Property ([OFTPClient](#oftpclient-component) Component)

Use SSL to access the [RemoteHost](#remotehost-property-oftpclient-component) .

## Syntax

```text
public bool UseSSL { get; set; }
```

## Default Value

False

## Remarks

Use this property to determine whether the component uses SSL to connect with the [RemoteHost](#remotehost-property-oftpclient-component).

This property is only valid when using version 2.0 of the protocol.

Note: Setting this property to True will set [RemotePort](#remoteport-property-oftpclient-component) to 6619.

This property is not available at design time.

# Version Property ([OFTPClient](#oftpclient-component) Component)

Which version of the OFTP protocol the component is using.

## Syntax

```text
public OFTPClientVersions Version { get; set; }
enum OFTPClientVersions {
  oftpVer12,
  oftpVer13,
  oftpVer14,
  oftpVer20
}
```

## Default Value

3

## Remarks

This property specifies which version of the OFTP protocol to use. Possible values are:

|  |  |
| --- | --- |
| 0 (oftpVer12) | 1.2 |
| 1 (oftpVer13) | 1.3 |
| 2 (oftpVer14) | 1.4 |
| 3 (oftpVer20 - default) | 2.0 |

 The default value is oftpVer20 (Version 2.0).

Note: Version 2.0 (oftpVer20) of the protocol must be used when using security functions. The following properties are only applicable when using Version 2.0:

- [UseSSL](#usessl-property-oftpclient-component)
- [SecureAuthentication](#secureauthentication-property-oftpclient-component)
- [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component)
- [Compress](#compress-property-oftpclient-component)

# VirtualFileDate Property ([OFTPClient](#oftpclient-component) Component)

The date/time stamp for the virtual file.

## Syntax

```text
public string VirtualFileDate { get; set; }
```

## Default Value

""

## Remarks

Set this to the date/time stamp for the virtual file before sending. If this is not set when sending a file, the current date/time will be used. This property will accept various date formats, but will return the following format only: "MM/dd/yyyy HH:mm:ss".

Supported date formats:

- ddd, d MMM yy HH:mm:ss zzz
- ddd, d MMM yyyy HH:mm:ss zzz
- d MMM yy HH:mm:ss zzz
- d MMM yyyy HH:mm:ss zzz
- dd-MMM-yyyy HH:mm:ss
- ddd, d MMM yy HH:mm:ss zz
- ddd, d MMM yyyy HH:mm:ss zz
- ddd, d MMM yy HH:mm:ss zzz
- ddd, d MMM yyyy HH:mm:ss zzz
- ddd, d MMM yy HH:mm:ss z
- ddd, d MMM yyyy HH:mm:ss z
- ddd, dd MMM yyyy HH:mm:ss 'GMT'
- dddd, MMMM dd, yyyy h:mm:ss tt
- dddd, MMMM dd yyyy h:mm tt
- yyMMddHHmmssZ
- yyyyMMddHHmmssZ
- yyMMddHHmmsszzzz
- yyyyMMddHHmmsszzzz
- yyyyMMddHHmmssffff
- MM/dd/yyyy HH:mm:ss

# VirtualFileFormat Property ([OFTPClient](#oftpclient-component) Component)

The structure of the outgoing file.

## Syntax

```text
public OFTPClientVirtualFileFormats VirtualFileFormat { get; set; }
enum OFTPClientVirtualFileFormats {
  ffUnstructured,
  ffText,
  ffFixed,
  ffVariable
}
```

## Default Value

0

## Remarks

The following values are valid file formats for outgoing virtual files:

|  |  |
| --- | --- |
| 0 (Unstructured - default) | The outgoing file is binary and has not structure. There are no records in this type of file. |
| 1 (Text) | The outgoing file is a text file that consists of lines containing no more than 2048 characters terminated by CRLF. This type contains no records. |
| 2 (Fixed) | The outgoing file is in fixed file format, which means all records are of the same length. For fixed files, the component expects the file to be in text format with each line containing the [MaxRecordSize](#maxrecordsize-property-oftpclient-component) characters terminated by a CRLF. |
| 3 (Variable) | The outgoing file is a variable file format, meaning all records are of variable length and are no longer than [MaxRecordSize](#maxrecordsize-property-oftpclient-component). When using this format, the component will parse out each record as a line terminated by CRLF. Thus, this type of file must be a text file, and must contain lines with less than [MaxRecordSize](#maxrecordsize-property-oftpclient-component) characters. |

Note: When either [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) has been set to a value other than *slNone* or [Compress](#compress-property-oftpclient-component) has been set to true, all files become *ffUnstructured* except *ffVariable* files.

This property is not available at design time.

# VirtualFileSecurityLevel Property ([OFTPClient](#oftpclient-component) Component)

The level of security for the file.

## Syntax

```text
public OFTPClientVirtualFileSecurityLevels VirtualFileSecurityLevel { get; set; }
enum OFTPClientVirtualFileSecurityLevels {
  slNone,
  slEncrypted,
  slSigned,
  slEncryptedAndSigned
}
```

## Default Value

0

## Remarks

When sending files, set this value to the level of security for the next virtual file to send. After receiving a file, this will be set to the level of security of the last file received.

When encrypting a file, [RecipientCert](#recipientcert-property-oftpclient-component) must be set, and when signing a file, the [Certificate](#certificate-property-oftpclient-component) must be set.

The file will be processed to a temporary file before being sent.

This is only valid for version 2.0 of the protocol.

This property is not available at design time.

# ChangeDirection Method ([OFTPClient](#oftpclient-component) Component)

Sends a Change Direction (CD) command.

## Syntax

```text
public void ChangeDirection();

Async Version
public async Task ChangeDirection();
public async Task ChangeDirection(CancellationToken cancellationToken);
```

## Remarks

This method sends a Change Direction (CD) command to the remote host when called. In normal operation this should not be used. This should only be used if a condition arises where you must manually change the speaker when communicating with the remote host.

# Config Method ([OFTPClient](#oftpclient-component) Component)

Sets or retrieves a configuration setting.

## Syntax

```text
public string Config(string configurationString);

Async Version
public async Task<string> Config(string configurationString);
public async Task<string> Config(string configurationString, CancellationToken cancellationToken);
```

## Remarks

Config is a generic method available in every component. It is used to set and retrieve [configuration settings](#config-settings-oftpclient-component) for the component.

These settings are similar in functionality to properties, but they are rarely used. In order to avoid "polluting" the property namespace of the component, access to these *internal properties* is provided through the Config method.

To set a configuration setting named *PROPERTY*, you must call *Config("PROPERTY=VALUE")*, where *VALUE* is the value of the setting expressed as a string. For boolean values, use the strings "True", "False", "0", "1", "Yes", or "No" (case does not matter).

To read (query) the value of a [configuration setting](#config-settings-oftpclient-component), you must call *Config("PROPERTY")*. The value will be returned as a string.

# Connect Method ([OFTPClient](#oftpclient-component) Component)

This method connects to the FTP server without logging in.

## Syntax

```text
public void Connect();

Async Version
public async Task Connect();
public async Task Connect(CancellationToken cancellationToken);
```

## Remarks

This method establishes a connection with the [RemoteHost](#remotehost-property-oftpclient-component) but does not log in. In most cases, it is recommended to use the [Logon](#logon-method-oftpclient-component) method, which will both establish a connection and log in to the server.

This method may be useful in cases in which it is desirable to separate the connection and logon operations, for instance, confirming that a host is available by first creating the connection.

# Disconnect Method ([OFTPClient](#oftpclient-component) Component)

This method disconnects from the server without first logging off.

## Syntax

```text
public void Disconnect();

Async Version
public async Task Disconnect();
public async Task Disconnect(CancellationToken cancellationToken);
```

## Remarks

This method immediately disconnects from the server without first logging off.

In most cases, the [Logoff](#logoff-method-oftpclient-component) method should be used to log off and disconnect from the server. Call the Disconnect method in cases in which it is desirable to immediately disconnect without first logging off.

# DoEvents Method ([OFTPClient](#oftpclient-component) Component)

This method processes events from the internal message queue.

## Syntax

```text
public void DoEvents();

Async Version
public async Task DoEvents();
public async Task DoEvents(CancellationToken cancellationToken);
```

## Remarks

When DoEvents is called, the component processes any available events. If no events are available, it waits for a preset period of time, and then returns.

# ExchangeCertificate Method ([OFTPClient](#oftpclient-component) Component)

Exchange a certificate with the remote host.

## Syntax

```text
public void ExchangeCertificate(string certificateStore, int certificateExchangeType);

Async Version
public async Task ExchangeCertificate(string certificateStore, int certificateExchangeType);
public async Task ExchangeCertificate(string certificateStore, int certificateExchangeType, CancellationToken cancellationToken);
```

## Remarks

If the remote host supports the certificate exchange feature of OFTP 2.0 this method may be used to send and/or request certificates.

The *CertificateStore* parameter specifies the location of the certificate to be exchanged. In most cases this will be the path to a .cer file on disk. If the certificate is in another format or is installed to the Windows certificate store please see [ExchangeCertStoreType](#ExchangeCertStoreType) and [ExchangeCertSubject](#ExchangeCertSubject) for more information.

The *CertificateExchangeType* parameter determines the type of request. Possible values are:

|  |  |
| --- | --- |
| 0 | Request: The component will send the certificate file specified. The remote host will respond with a certificate of it's own. The response may be in a separate session. |
| 1 | Replace: The component will send the certificate file specified. No certificate is expected in response. The certificate sent here invalidates any previous certificates the remote host has stored. |
| 2 | Deliver: The component will send the certificate file specified. This is used to respond to a certificate request. It may also be used to send new additional certificates to the remote host. This will not invalidate previous certificates the remote host has stored. |

 When the remote host sends a certificate to the component the received certificate will be provided through the [CertificateReceived](#certificatereceived-event-oftpclient-component) event.

# ImportTrustedCerts Method ([OFTPClient](#oftpclient-component) Component)

Imports a list of trusted CA certificates.

## Syntax

```text
public void ImportTrustedCerts();

Async Version
public async Task ImportTrustedCerts();
public async Task ImportTrustedCerts(CancellationToken cancellationToken);
```

## Remarks

When ImportTrustedCerts is called the component will import the CA certificates from the source specified by [TrustedCertsData](#TrustedCertsData) into the [TrustedCerts](#trustedcerts-property-oftpclient-component) collection.

The component will then validate the trust of certificates when they are loaded.

If trusted CA certificates are not imported no validation will occur (default).

See also [FailOnUntrustedCert](#FailOnUntrustedCert).

# Interrupt Method ([OFTPClient](#oftpclient-component) Component)

This method interrupts the current action.

## Syntax

```text
public void Interrupt();

Async Version
public async Task Interrupt();
public async Task Interrupt(CancellationToken cancellationToken);
```

## Remarks

This method interrupts the current action. If you use [SendFile](#sendfile-method-oftpclient-component) to upload a file, the component will run synchronously until the upload is completed. This method will allow you to stop the file from uploading without disconnecting from the host.

# Logoff Method ([OFTPClient](#oftpclient-component) Component)

Logoff from the OFTP server.

## Syntax

```text
public void Logoff();

Async Version
public async Task Logoff();
public async Task Logoff(CancellationToken cancellationToken);
```

## Remarks

Logoff from the OFTP server. If that fails, the connection is terminated by the local host.

# Logon Method ([OFTPClient](#oftpclient-component) Component)

Logon to the OFTP [RemoteHost](#remotehost-property-oftpclient-component) using the current client credentials.

## Syntax

```text
public void Logon();

Async Version
public async Task Logon();
public async Task Logon(CancellationToken cancellationToken);
```

## Remarks

Logon to the OFTP server using the current [ClientSSIDCode](#clientssidcode-property-oftpclient-component), [ClientSFIDCode](#clientsfidcode-property-oftpclient-component), and [ClientPassword](#clientpassword-property-oftpclient-component). The component will also check the corresponding server credentials, [ServerSSIDCode](#serverssidcode-property-oftpclient-component), [ServerSFIDCode](#serversfidcode-property-oftpclient-component), and [ServerPassword](#serverpassword-property-oftpclient-component).

# ReceiveFiles Method ([OFTPClient](#oftpclient-component) Component)

Receive any files queued to be sent from the server.

## Syntax

```text
public void ReceiveFiles();

Async Version
public async Task ReceiveFiles();
public async Task ReceiveFiles(CancellationToken cancellationToken);
```

## Remarks

This method connects to the server, and receives any files the server has in its outgoing queue to this particular partner. The files are downloaded to the directory specified by the [DownloadDirectory](#downloaddirectory-property-oftpclient-component) property.

# Reset Method ([OFTPClient](#oftpclient-component) Component)

Resets the state of the control.

## Syntax

```text
public void Reset();

Async Version
public async Task Reset();
public async Task Reset(CancellationToken cancellationToken);
```

## Remarks

**Reset** resets the state of the component. All properties will be set to their default values.

# SendEndResponse Method ([OFTPClient](#oftpclient-component) Component)

Sends an EERP/NERP asynchronously.

## Syntax

```text
public void SendEndResponse(string virtualFileName, string virtualFileDate, string destination, string originator, string creator, int reasonCode, string reasonText, string fileHash, string signature);

Async Version
public async Task SendEndResponse(string virtualFileName, string virtualFileDate, string destination, string originator, string creator, int reasonCode, string reasonText, string fileHash, string signature);
public async Task SendEndResponse(string virtualFileName, string virtualFileDate, string destination, string originator, string creator, int reasonCode, string reasonText, string fileHash, string signature, CancellationToken cancellationToken);
```

## Remarks

This method sends an EERP/NERP. By default the component will automatically respond with an EERP/NERP when receiving a file. To respond asynchronously instead this method may be used.

To respond asynchronously first set the *SendEndResponse* parameter of the [EndTransfer](#endtransfer-event-oftpclient-component) event to False. This instructs the component to not send a response automatically. Within the [EndTransfer](#endtransfer-event-oftpclient-component) event you must also save the values that are required parameters for this method. This includes *FileHash*, *VirtualFileDate*, and *VirtualFileName*. Note: [VirtualFileDateFormat](#VirtualFileDateFormat) must be set to a format that includes the necessary level of accuracy.

*Destination* should be set to the SFID of the remote host.

*Originator* should be set to the SFID of the local system. In the case that the component is being used as part of a gateway process to forward traffic to another OFTP host this may be set to the SFID of that host instead.

*Creator* should be set to the SFID of the local system.

*Signature* is only applicable if the application is acting as a routing application. In all other cases this should be set to empty string. In the case where the application is acting as a routing application the end response is being forwarded to another entity for processing. The *Signature* should be set to the value received in the [EndResponse](#endresponse-event-oftpclient-component) event (if populated).

*ReasonCode* and *ReasonText* are used to specify error information. If *ReasonCode* is set to 0 the component will send an EERP. If *ReasonCode* is set to any non-zero value the component will send a NERP. Common values are:

|  |  |
| --- | --- |
| ReasonCode | ReasonText |
| 3 | User Code Not Known |
| 4 | Invalid Password |
| 9 | Unspecified Reason |
| 11 | Invalid FileName |
| 12 | Invalid Destination |
| 13 | Invalid Origin |
| 14 | Invalid Storage Record Format |
| 15 | Maximum Record Length Not Supported |
| 16 | File Size Too Big |
| 20 | Invalid Record Count |
| 21 | Invalid Byte Count |
| 22 | Access Method Failure |
| 23 | Duplicate File |
| 24 | File Direction Refused |
| 25 | Cipher Suite Not Supported |
| 26 | Encrypted File Not Allowed |
| 27 | Unencrypted File Not Allowed |
| 28 | Compression Not Allowed |
| 29 | Signed File Not Allowed |
| 30 | Unsigned File Not Allowed |
| 31 | File Signature Not Valid |
| 32 | File Decompression Failed |
| 33 | File Decryption Failed |
| 34 | File Processing Failed |
| 35 | Not Delivered To Recipient |
| 36 | Not Acknowledged By Recipient |
| 50 | Transmission Stopped By The Operator |
| 90 | File Size Incompatible With Recipient's Protocol Version |
| 99 | Unspecified Reason |

# SendFile Method ([OFTPClient](#oftpclient-component) Component)

Send the specified file to the server.

## Syntax

```text
public void SendFile(string localFile, string virtualFileName);

Async Version
public async Task SendFile(string localFile, string virtualFileName);
public async Task SendFile(string localFile, string virtualFileName, CancellationToken cancellationToken);
```

## Remarks

This method connects to the server, and uploads the specified file to the server. The *LocalFile* parameter contains the path and name of the file to send to the server. The *VirtualFileName* parameter contains the virtual file name of the file being sent. If this parameter is left as an empty string, the component will use the filename contained in the *LocalFile* parameter by default.

Note: When [SetUploadStream](#setuploadstream-method-oftpclient-component) has been called with a valid input stream, the data will be uploaded from there instead of the *LocalFile*.

# SetDownloadStream Method ([OFTPClient](#oftpclient-component) Component)

Sets the stream to which the downloaded file is written.

## Syntax

```text
public void SetDownloadStream(System.IO.Stream downloadStream);

Async Version
public async Task SetDownloadStream(System.IO.Stream downloadStream);
public async Task SetDownloadStream(System.IO.Stream downloadStream, CancellationToken cancellationToken);
```

## Remarks

When set, the file data will be written to the stream when downloaded from the server. The stream should be open and normally set to position 0.

The component will automatically close this stream if [CloseStreamAfterTransfer](#CloseStreamAfterTransfer) is *true* (default).

It is recommended to call this method from within the [AcceptFile](#acceptfile-event-oftpclient-component) event to ensure each received file is set to the intended stream object.

# SetUploadStream Method ([OFTPClient](#oftpclient-component) Component)

Sets the stream to be uploaded to the server.

## Syntax

```text
public void SetUploadStream(System.IO.Stream uploadStream);

Async Version
public async Task SetUploadStream(System.IO.Stream uploadStream);
public async Task SetUploadStream(System.IO.Stream uploadStream, CancellationToken cancellationToken);
```

## Remarks

When set, the data will be read from the stream when uploaded to the server. The stream should be open and normally set to position 0.

The component will automatically close this stream if [CloseStreamAfterTransfer](#CloseStreamAfterTransfer) is true (default). If the stream is closed, you will need to call SetUploadStream again before the next send.

The content of the stream will be read from the current position all the way to the end.

# ValidateCert Method ([OFTPClient](#oftpclient-component) Component)

Validates the certificate with private key.

## Syntax

```text
public bool ValidateCert();

Async Version
public async Task<bool> ValidateCert();
public async Task<bool> ValidateCert(CancellationToken cancellationToken);
```

## Remarks

This method optionally validates the certificate specified by [Certificate](#certificate-property-oftpclient-component). It is not required to validate the certificate from a technical perspective, but may be desired to ensure the recipient's certificate is valid and issued by a trusted authority.

Before calling this method call [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) to load the trusted certification information.

When this method is called the component:

- Validates the certificate has not expired
- Validates the certificate was issued by a CA in the [TrustedCerts](#trustedcerts-property-oftpclient-component) collection. If the certificate is self-signed this step is skipped.
- Validates the certificate has not been revoked. Note that the revocation check will only make use of the CRL distribution point identified in the certificate's extension. If the certificate does not contain a CRL distribution point extension this step is skipped.

# ValidateRecipientCert Method ([OFTPClient](#oftpclient-component) Component)

Validates the recipient certificate.

## Syntax

```text
public bool ValidateRecipientCert();

Async Version
public async Task<bool> ValidateRecipientCert();
public async Task<bool> ValidateRecipientCert(CancellationToken cancellationToken);
```

## Remarks

This method optionally validates the certificate specified by [RecipientCert](#recipientcert-property-oftpclient-component). It is not required to validate the certificate from a technical perspective, but may be desired to ensure the recipient's certificate is valid and issued by a trusted authority.

Before calling this method call [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) to load the trusted certification information.

When this method is called the component:

- Validates the certificate has not expired
- Validates the certificate was issued by a CA in the [TrustedCerts](#trustedcerts-property-oftpclient-component) collection. If the certificate is self-signed this step is skipped.
- Validates the certificate has not been revoked. Note that the revocation check will only make use of the CRL distribution point identified in the certificate's extension. If the certificate does not contain a CRL distribution point extension this step is skipped.

# AcceptFile Event ([OFTPClient](#oftpclient-component) Component)

Fired when the client receives a file.

## Syntax

```text
public event OnAcceptFileHandler OnAcceptFile;

public delegate void OnAcceptFileHandler(object sender, OFTPClientAcceptFileEventArgs e);

public class OFTPClientAcceptFileEventArgs : EventArgs {
  public string VirtualFileName { get; }
  public string VirtualFileDate { get; }
  public string Destination { get; }
  public string Originator { get; }
  public bool Accept { get; set; }
  public string FileName { get; set; }
  public bool Overwrite { get; set; }
  public int ErrorCode { get; set; }
  public string ErrorDescription { get; set; }
}
```

## Remarks

This event controls the behavior when the client receives a file.

*VirtualFileName* holds the name of the file being received.

*VirtualFileDate* holds the date associated with the file in the format specified by [VirtualFileDateFormat](#VirtualFileDateFormat). The default value is "MM/dd/yyyy HH:mm:ss".

*Destination* identifies the receiver (SFID) code in the send file request. If the file was intended for this server this will match the value in [ServerSFIDCode](#serversfidcode-property-oftpclient-component)

*Originator* identifies the sender (SFID) code in the send file request.

*Accept* is true by default, and must be set to False in order to reject the file.

*Filename* will be populated with the full path and filename that will be written. It may be changed within this event to specify a new location. The Filename is determined by combining the path specified in [DownloadDirectory](#@@OFTPClient_Connections@@_f_DownloadDirectory) and the name received from the client.

*Overwrite* is false by default, but may be set to true to overwrite existing files on disk.

*ErrorCode* controls the error returned to the client when *Accept* is set to False. If this is not set the component will use a value of 99 to indicate a general error.

*ErrorDescription* may also be set to include an error message. If this is not set the component will automatically include an error message based on the *ErrorCode* specified. Common error codes and their corresponding error messages are listed below.

|  |  |
| --- | --- |
| ErrorCode | ErrorMessage |
| 1 | Invalid filename. |
| 2 | Invalid destination. |
| 3 | Invalid origin. |
| 4 | Storage record format not supported. |
| 5 | Maximum record length not supported. |
| 6 | File size is too big. |
| 10 | Invalid record count. |
| 11 | Invalid byte count. |
| 12 | Access method failure. |
| 13 | Duplicate file. |
| 14 | File direction refused. |
| 15 | Cipher suite not supported. |
| 16 | Encrypted file not allowed. |
| 17 | Unencrypted file not allowed. |
| 18 | Compression not allowed. |
| 19 | Signed file not allowed. |
| 20 | Unsigned file not allowed. |
| 99 | Unspecified reason. |

# CertificateReceived Event ([OFTPClient](#oftpclient-component) Component)

Fired when a certificate is received from the remote host.

## Syntax

```text
public event OnCertificateReceivedHandler OnCertificateReceived;

public delegate void OnCertificateReceivedHandler(object sender, OFTPClientCertificateReceivedEventArgs e);

public class OFTPClientCertificateReceivedEventArgs : EventArgs {
  public string CertificateFileName { get; }
  public int CertificateExchangeType { get; }
}
```

## Remarks

This event provides information about the certificate file that was sent by the remote host.

When the remote host sends a certificate using the Certificate Exchange feature of OFTP 2.0, this event provides information about it. The certificate file will be written to the [DownloadDirectory](#downloaddirectory-property-oftpclient-component). After the file is written to [DownloadDirectory](#downloaddirectory-property-oftpclient-component) this event will fire.

The *CertificateFilename* parameter holds the filename of the received certificate.

The *CertificateExchangeType* parameter identifies the type of request associated with the certificate. Possible values are:

|  |  |
| --- | --- |
| 0 | Request: The component received a certificate and request from the remote host. Respond using the [ExchangeCertificate](#exchangecertificate-method-oftpclient-component) method using a CertificateExchangeType of 3 (Deliver). The response may be in a separate session. |
| 1 | Replace: The component received a certificate from the remote host. No response is expected. The certificate received here invalidates any previously stored certificates for this configuration. |
| 2 | Deliver: The component received a certificate from the remote host. This is either a response to a certificate request, or a new additional certificates from the remote host. This will not invalidate previous certificates stored for this configuration. |

# EndResponse Event ([OFTPClient](#oftpclient-component) Component)

Fired every time an end response is received from the server.

## Syntax

```text
public event OnEndResponseHandler OnEndResponse;

public delegate void OnEndResponseHandler(object sender, OFTPClientEndResponseEventArgs e);

public class OFTPClientEndResponseEventArgs : EventArgs {
  public string VirtualFileName { get; }
  public string VirtualFileDate { get; }
  public string Destination { get; }
  public string Originator { get; }
  public string Creator { get; }
  public int ReasonCode { get; }
  public string ReasonText { get; }
  public string FileHash { get; set; }
  public string Signature { get; }
  public int Direction { get; }
}
```

## Remarks

This event contains information received from an either an End-To-End Response or a Negative End Response received from the server.

An End-To-End Response will not contain values for the *ReasonCode*, *ReasonText*, or *Creator* parameters.

*VirtualFileName* specifies the name of the file.

*VirtualFileDate* holds the VirtualFileDate value in the format specified by [VirtualFileDateFormat](#VirtualFileDateFormat). The default value is "MM/dd/yyyy HH:mm:ss".

*Destination* is the SFID of the destination system (this component).

*Originator* identifies the system that originated the end response. This is typically the same as *Creator* and holds the remote system's SFID.

*Creator* is the SFID of the remote system.

*Direction* specifies whether the end response is being received or sent. Possible values are:

|  |  |
| --- | --- |
| 0 | Received |
| 1 | Sent |

 By default the component will only fire this event for received end responses. To configure the component to fire the event for both send and received end responses set [FireEndResponseOnSend](#FireEndResponseOnSend) to True.

*FileHash* is populated if the OFTP Version is 2.0 and a signed receipt was originally requested. FileHash may also be specified with the expected value in the case where an asynchronous EndResponse is received. The expected value may be obtained from the [EndTransfer](#endtransfer-event-oftpclient-component) event when initially sending the file.

*Signature* is only applicable when the OFTP version is 2.0 and the application is acting as a routing application where the end response will be forwarded on to another entity. In this case *Signature* will be populated if the end response is signed. This should be stored and supplied when forwarding the response with the [SendEndResponse](#sendendresponse-method-oftpclient-component) method.

*ReasonCode* and *ReasonText* identify the error if a Negative End Response (NERP) was received. A value of 0 indicates there was no an error and the response is an End-To-End Response (EERP). Common values are:

|  |  |
| --- | --- |
| ReasonCode | ReasonText |
| 3 | User Code Not Known |
| 4 | Invalid Password |
| 9 | Unspecified Reason |
| 11 | Invalid FileName |
| 12 | Invalid Destination |
| 13 | Invalid Origin |
| 14 | Invalid Storage Record Format |
| 15 | Maximum Record Length Not Supported |
| 16 | File Size Too Big |
| 20 | Invalid Record Count |
| 21 | Invalid Byte Count |
| 22 | Access Method Failure |
| 23 | Duplicate File |
| 24 | File Direction Refused |
| 25 | Cipher Suite Not Supported |
| 26 | Encrypted File Not Allowed |
| 27 | Unencrypted File Not Allowed |
| 28 | Compression Not Allowed |
| 29 | Signed File Not Allowed |
| 30 | Unsigned File Not Allowed |
| 31 | File Signature Not Valid |
| 32 | File Decompression Failed |
| 33 | File Decryption Failed |
| 34 | File Processing Failed |
| 35 | Not Delivered To Recipient |
| 36 | Not Acknowledged By Recipient |
| 50 | Transmission Stopped By The Operator |
| 90 | File Size Incompatible With Recipient's Protocol Version |
| 99 | Unspecified Reason |

# EndTransfer Event ([OFTPClient](#oftpclient-component) Component)

Fired when a file finishes transferring.

## Syntax

```text
public event OnEndTransferHandler OnEndTransfer;

public delegate void OnEndTransferHandler(object sender, OFTPClientEndTransferEventArgs e);

public class OFTPClientEndTransferEventArgs : EventArgs {
  public int Direction { get; }
  public string LocalFile { get; }
  public string VirtualFileName { get; }
  public string VirtualFileDate { get; }
  public string Destination { get; }
  public string Originator { get; }
  public int ReasonCode { get; }
  public string ReasonText { get; }
  public long FileSize { get; }
  public string FileHash { get; }
  public bool SendEndResponse { get; set; }
}
```

## Remarks

The EndTransfer event is fired when a file is sent or received by the component.

The *FileSize* parameter gives the size of the file that was sent or received.

The *Direction* parameter shows whether the client or the server is sending the data.

|  |  |
| --- | --- |
| 0 (Client) | The file originated from the client. |
| 1 (Server) | The file originated from the server. |

*VirtualFileName* holds the filename.

*VirtualFileDate* holds the date associated with the file in the format specified by [VirtualFileDateFormat](#VirtualFileDateFormat). The default value is "MM/dd/yyyy HH:mm:ss".

*Originator* identifies the sender (SFID) code in the send file request.

*Destination* identifies the receiver (SFID) code in the send file request.

*SendEndResponse* indicates whether the EERP/NERP for this request should be sent synchronously or asynchronously. When this parameter is True (default) the component will automatically respond with an EERP/NERP synchronously. To respond asynchronously set this parameter to False. You may then use the [SendEndResponse](#sendendresponse-method-oftpclient-component) method to send the response at a later time. See [SendEndResponse](#sendendresponse-method-oftpclient-component) for more details. Note: [VirtualFileDateFormat](#VirtualFileDateFormat) must be set to a format that includes the necessary level of accuracy.

*FileHash* holds the hash of the file being transmitted. This is only applicable when the OFTP version is 2.0 and the sender requested a signed receipt. When receiving files this value should be saved if you wish to respond asynchronously using [SendEndResponse](#sendendresponse-method-oftpclient-component). See [SendEndResponse](#sendendresponse-method-oftpclient-component) for more details.

*LocalFile* holds the full path to the file that will be written.

*ReasonCode* and *ReasonText* identify the error if a Negative End Response (NERP) was received. A value of 0 indicates there was no an error and the response is an End-To-End Response (EERP). Common values are:

|  |  |
| --- | --- |
| ReasonCode | ReasonText |
| 3 | User Code Not Known |
| 4 | Invalid Password |
| 9 | Unspecified Reason |
| 11 | Invalid FileName |
| 12 | Invalid Destination |
| 13 | Invalid Origin |
| 14 | Invalid Storage Record Format |
| 15 | Maximum Record Length Not Supported |
| 16 | File Size Too Big |
| 20 | Invalid Record Count |
| 21 | Invalid Byte Count |
| 22 | Access Method Failure |
| 23 | Duplicate File |
| 24 | File Direction Refused |
| 25 | Cipher Suite Not Supported |
| 26 | Encrypted File Not Allowed |
| 27 | Unencrypted File Not Allowed |
| 28 | Compression Not Allowed |
| 29 | Signed File Not Allowed |
| 30 | Unsigned File Not Allowed |
| 31 | File Signature Not Valid |
| 32 | File Decompression Failed |
| 33 | File Decryption Failed |
| 34 | File Processing Failed |
| 35 | Not Delivered To Recipient |
| 36 | Not Acknowledged By Recipient |
| 50 | Transmission Stopped By The Operator |
| 90 | File Size Incompatible With Recipient's Protocol Version |
| 99 | Unspecified Reason |

# Error Event ([OFTPClient](#oftpclient-component) Component)

Fired when information is available about errors during data delivery.

## Syntax

```text
public event OnErrorHandler OnError;

public delegate void OnErrorHandler(object sender, OFTPClientErrorEventArgs e);

public class OFTPClientErrorEventArgs : EventArgs {
  public int ErrorCode { get; }
  public string Description { get; }
}
```

## Remarks

The Error event is fired in case of exceptional conditions during message processing. Normally the component throws an exception.

The *ErrorCode* parameter contains an error code, and the *Description* parameter contains a textual description of the error. For a list of valid error codes and their descriptions, please refer to the [Error Codes](#trappable-errors-oftpclient-component) section.

# Log Event ([OFTPClient](#oftpclient-component) Component)

Fires once for each log message.

## Syntax

```text
public event OnLogHandler OnLog;

public delegate void OnLogHandler(object sender, OFTPClientLogEventArgs e);

public class OFTPClientLogEventArgs : EventArgs {
  public int LogLevel { get; }
  public string Message { get; }
  public string LogType { get; }
}
```

## Remarks

This event fires once for each log message generated by the component. The verbosity is controlled by the [LogLevel](#LogLevel) setting.

*LogLevel* indicates the level of message. Possible values are:

|  |  |
| --- | --- |
| 0 (None) | No messages are logged. |
| 1 (Info - Default) | Informational events such as OFTP commands which are sent and received. |
| 2 (Verbose) | Detailed data such as individual packet information is logged. |
| 3 (Debug) | Debug data including all relevant sent and received bytes are logged. |

*Message* is the log entry.

*LogType* identifies the type of log entry. Possible values are:

- "Info"
- "OFTP"

# PITrail Event ([OFTPClient](#oftpclient-component) Component)

Fired when any protocol level communication occurs.

## Syntax

```text
public event OnPITrailHandler OnPITrail;

public delegate void OnPITrailHandler(object sender, OFTPClientPITrailEventArgs e);

public class OFTPClientPITrailEventArgs : EventArgs {
  public int Direction { get; }
  public string Data { get; }  public byte[] DataB { get; }
  public int CommandId { get; }
  public string CommandDescription { get; }
}
```

## Remarks

This event provides information about the protocol level communication between the client and server.

The *Direction* parameter specifies who sent the command.

|  |  |
| --- | --- |
| 0 (Client) | The command originated from the connected client. |
| 1 (Server) | The command originated from the server. |

The *CommandId* and *CommandDescription* parameters specify which command was sent. The table below shows possible values.

|  |  |
| --- | --- |
| CommandId | CommandDescription |
| 50 | SFPA (Start File Positive Answer) |
| 51 | SFNA (Start File Negative Answer) |
| 52 | EFPA (End File Positive Answer) |
| 53 | EFNA (End File Negative Answer) |
| 65 | AUCH (Authentication Challenge) |
| 67 | CDT (Set Credit) |
| 68 | DATA (Data Exchange Buffer) |
| 69 | EERP (End to End Response) |
| 70 | ESID (End Session) |
| 72 | SFID (Start File) |
| 73 | SSRM (Start Session Ready Message) |
| 74 | SECD (Security Change Direction) |
| 78 | NERP (Negative End Response) |
| 80 | RTR (Ready To Receive) |
| 82 | CD (Change Direction) |
| 83 | AURP (Authentication Response) |
| 84 | EFID (End File) |
| 88 | SSID (Start Session) |

The *Data* parameter contains the raw OFTP packet.

# SSLServerAuthentication Event ([OFTPClient](#oftpclient-component) Component)

Fired after the server presents its certificate to the client.

## Syntax

```text
public event OnSSLServerAuthenticationHandler OnSSLServerAuthentication;

public delegate void OnSSLServerAuthenticationHandler(object sender, OFTPClientSSLServerAuthenticationEventArgs e);

public class OFTPClientSSLServerAuthenticationEventArgs : EventArgs {
  public string CertEncoded { get; }  public byte[] CertEncodedB { get; }
  public string CertSubject { get; }
  public string CertIssuer { get; }
  public string Status { get; }
  public bool Accept { get; set; }
}
```

## Remarks

During this event, the client can decide whether or not to continue with the connection process. The *Accept* parameter is a recommendation on whether to continue or close the connection. This is just a suggestion: application software must use its own logic to determine whether or not to continue.

 When *Accept* is False, *Status* shows why the verification failed (otherwise, *Status* contains the string *OK*). If it is decided to continue, you can override and accept the certificate by setting the *Accept* parameter to True.

# SSLStatus Event ([OFTPClient](#oftpclient-component) Component)

Fired when secure connection progress messages are available.

## Syntax

```text
public event OnSSLStatusHandler OnSSLStatus;

public delegate void OnSSLStatusHandler(object sender, OFTPClientSSLStatusEventArgs e);

public class OFTPClientSSLStatusEventArgs : EventArgs {
  public string Message { get; }
}
```

## Remarks

The event is fired for informational and logging purposes only. This event tracks the progress of the connection.

# StartTransfer Event ([OFTPClient](#oftpclient-component) Component)

Fired when a document starts transferring.

## Syntax

```text
public event OnStartTransferHandler OnStartTransfer;

public delegate void OnStartTransferHandler(object sender, OFTPClientStartTransferEventArgs e);

public class OFTPClientStartTransferEventArgs : EventArgs {
  public int Direction { get; }
  public string LocalFile { get; set; }
  public string VirtualFileName { get; }
  public string VirtualFileDate { get; }
  public string Destination { get; }
  public string Originator { get; }
}
```

## Remarks

This event fires when a file transfer begins.

*Direction* specifies if the client or server sent the file.

|  |  |
| --- | --- |
| 0 (Client) | The file originated from the client. |
| 1 (Server) | The file originated from the server. |

*VirtualFileName* holds the filename.

*VirtualFileDate* holds the date associated with the file in the format "MM/dd/yyyy HH:mm:ss".

*Originator* identifies the sender (SFID) code in the send file request.

*Destination* identifies the receiver (SFID) code in the send file request.

*LocalFile* holds the full path to the file that will be written.

# Transfer Event ([OFTPClient](#oftpclient-component) Component)

Fired while a document transfers (delivers document).

## Syntax

```text
public event OnTransferHandler OnTransfer;

public delegate void OnTransferHandler(object sender, OFTPClientTransferEventArgs e);

public class OFTPClientTransferEventArgs : EventArgs {
  public int Direction { get; }
  public string LocalFile { get; }
  public string VirtualFileName { get; }
  public string VirtualFileDate { get; }
  public string Destination { get; }
  public string Originator { get; }
  public long BytesTransferred { get; }
  public string Text { get; }  public byte[] TextB { get; }
}
```

## Remarks

The *Text* parameter contains the portion of the document text being retrieved. It is empty if data is being posted to the server.

The *BytesTransferred* parameter contains the number of bytes transferred in this *Direction* since the beginning of the document text.

The *Direction* parameter shows whether the client (0) or the server (1) is sending the data.

*VirtualFileName* holds the filename.

*VirtualFileDate* holds the date associated with the file in the format specified by [VirtualFileDateFormat](#VirtualFileDateFormat). The default value is "MM/dd/yyyy HH:mm:ss".

*Originator* identifies the sender (SFID) code in the send file request.

*Destination* identifies the receiver (SFID) code in the send file request.

*LocalFile* holds the full path to the file that will be written.

# Certificate Type

This is the digital certificate being used.

## Remarks

This type describes the current digital certificate. The certificate may be a public or private key. The fields are used to identify or select certificates.

The following fields are available:

- [EffectiveDate](#Certificate_f_EffectiveDate)

- [ExpirationDate](#Certificate_f_ExpirationDate)

- [ExtendedKeyUsage](#Certificate_f_ExtendedKeyUsage)

- [Fingerprint](#Certificate_f_Fingerprint)

- [FingerprintSHA1](#Certificate_f_FingerprintSHA1)

- [FingerprintSHA256](#Certificate_f_FingerprintSHA256)

- [Issuer](#Certificate_f_Issuer)

- [PrivateKey](#Certificate_f_PrivateKey)

- [PrivateKeyAvailable](#Certificate_f_PrivateKeyAvailable)

- [PrivateKeyContainer](#Certificate_f_PrivateKeyContainer)

- [PublicKey](#Certificate_f_PublicKey)

- [PublicKeyAlgorithm](#Certificate_f_PublicKeyAlgorithm)

- [PublicKeyLength](#Certificate_f_PublicKeyLength)

- [SerialNumber](#Certificate_f_SerialNumber)

- [SignatureAlgorithm](#Certificate_f_SignatureAlgorithm)

- [Store](#Certificate_f_Store)

- [StorePassword](#Certificate_f_StorePassword)

- [StoreType](#Certificate_f_StoreType)

- [SubjectAltNames](#Certificate_f_SubjectAltNames)

- [ThumbprintMD5](#Certificate_f_ThumbprintMD5)

- [ThumbprintSHA1](#Certificate_f_ThumbprintSHA1)

- [ThumbprintSHA256](#Certificate_f_ThumbprintSHA256)

- [Usage](#Certificate_f_Usage)

- [UsageFlags](#Certificate_f_UsageFlags)

- [Version](#Certificate_f_Version)

- [Subject](#Certificate_f_Subject)

- [Encoded](#Certificate_f_Encoded)

## Fields

 **EffectiveDate** *string (read-only)*
Default: ""

The date on which this certificate becomes valid. Before this date, it is not valid. The date is localized to the system's time zone. The following example illustrates the format of an encoded date:

23-Jan-2000 15:00:00.

 **ExpirationDate** *string (read-only)*
Default: ""

The date on which the certificate expires. After this date, the certificate will no longer be valid. The date is localized to the system's time zone. The following example illustrates the format of an encoded date:

23-Jan-2001 15:00:00.

 **ExtendedKeyUsage** *string (read-only)*
Default: ""

A comma-delimited list of extended key usage identifiers. These are the same as ASN.1 object identifiers (OIDs).

 **Fingerprint** *string (read-only)*
Default: ""

The hex-encoded, 16-byte MD5 fingerprint of the certificate. This property is primarily used for keys which do not have a corresponding X.509 public certificate, such as PEM keys that only contain a private key. It is commonly used for SSH keys.

The following example illustrates the format: *bc:2a:72:af:fe:58:17:43:7a:5f:ba:5a:7c:90:f7:02*

 **FingerprintSHA1** *string (read-only)*
Default: ""

The hex-encoded, 20-byte SHA-1 fingerprint of the certificate. This property is primarily used for keys which do not have a corresponding X.509 public certificate, such as PEM keys that only contain a private key. It is commonly used for SSH keys.

The following example illustrates the format: *30:7b:fa:38:65:83:ff:da:b4:4e:07:3f:17:b8:a4:ed:80:be:ff:84*

 **FingerprintSHA256** *string (read-only)*
Default: ""

The hex-encoded, 32-byte SHA-256 fingerprint of the certificate. This property is primarily used for keys which do not have a corresponding X.509 public certificate, such as PEM keys that only contain a private key. It is commonly used for SSH keys.

The following example illustrates the format: *6a:80:5c:33:a9:43:ea:b0:96:12:8a:64:96:30:ef:4a:8a:96:86:ce:f4:c7:be:10:24:8e:2b:60:9e:f3:59:53*

 **Issuer** *string (read-only)*
Default: ""

The issuer of the certificate. This field contains a string representation of the name of the issuing authority for the certificate.

 **PrivateKey** *string (read-only)*
Default: ""

The private key of the certificate (if available). The key is provided as PEM/Base64-encoded data.

NOTE: The [PrivateKey](#Certificate_f_PrivateKey) may be available but not exportable. In this case, [PrivateKey](#Certificate_f_PrivateKey) returns an empty string.

 **PrivateKeyAvailable** *bool (read-only)*
Default: False

Whether a [PrivateKey](#Certificate_f_PrivateKey) is available for the selected certificate. If [PrivateKeyAvailable](#Certificate_f_PrivateKeyAvailable) is True, the certificate may be used for authentication purposes (e.g., server authentication).

 **PrivateKeyContainer** *string (read-only)*
Default: ""

The name of the [PrivateKey](#Certificate_f_PrivateKey) container for the certificate (if available). This functionality is available only on Windows platforms.

 **PublicKey** *string (read-only)*
Default: ""

The public key of the certificate. The key is provided as PEM/Base64-encoded data.

 **PublicKeyAlgorithm** *string (read-only)*
Default: ""

The textual description of the certificate's public key algorithm. The property contains either the name of the algorithm (e.g., "RSA" or "RSA_DH") or an object identifier (OID) string representing the algorithm.

 **PublicKeyLength** *int (read-only)*
Default: 0

The length of the certificate's public key (in bits). Common values are 512, 1024, and 2048.

 **SerialNumber** *string (read-only)*
Default: ""

The serial number of the certificate encoded as a string. The number is encoded as a series of hexadecimal digits, with each pair representing a byte of the serial number.

 **SignatureAlgorithm** *string (read-only)*
Default: ""

The text description of the certificate's signature algorithm. The property contains either the name of the algorithm (e.g., "RSA" or "RSA_MD5RSA") or an object identifier (OID) string representing the algorithm.

 **Store** *string*
Default: "MY"

The name of the certificate store for the client certificate.

The [StoreType](#Certificate_f_StoreType) field denotes the type of the certificate store specified by [Store](#Certificate_f_Store). If the store is password-protected, specify the password in [StorePassword](#Certificate_f_StorePassword).

[Store](#Certificate_f_Store) is used in conjunction with the [Subject](#Certificate_f_Subject) field to specify client certificates. If [Store](#Certificate_f_Store) has a value, and [Subject](#Certificate_f_Subject) or [Encoded](#Certificate_f_Encoded) is set, a search for a certificate is initiated. Please see the [Subject](#Certificate_f_Subject) field for details.

 Designations of certificate stores are platform dependent.

The following designations are the most common User and Machine certificate stores in Windows:

|  |  |
| --- | --- |
| MY | A certificate store holding personal certificates with their associated private keys. |
| CA | Certifying authority certificates. |
| ROOT | Root certificates. |

When the certificate store type is *cstPFXFile*, this property must be set to the name of the file. When the type is *cstPFXBlob*, the property must be set to the binary contents of a PFX file (i.e., PKCS#12 certificate store).

 **StoreB** *byte []*
Default: "MY"

The name of the certificate store for the client certificate.

The [StoreType](#Certificate_f_StoreType) field denotes the type of the certificate store specified by [Store](#Certificate_f_Store). If the store is password-protected, specify the password in [StorePassword](#Certificate_f_StorePassword).

[Store](#Certificate_f_Store) is used in conjunction with the [Subject](#Certificate_f_Subject) field to specify client certificates. If [Store](#Certificate_f_Store) has a value, and [Subject](#Certificate_f_Subject) or [Encoded](#Certificate_f_Encoded) is set, a search for a certificate is initiated. Please see the [Subject](#Certificate_f_Subject) field for details.

 Designations of certificate stores are platform dependent.

The following designations are the most common User and Machine certificate stores in Windows:

|  |  |
| --- | --- |
| MY | A certificate store holding personal certificates with their associated private keys. |
| CA | Certifying authority certificates. |
| ROOT | Root certificates. |

When the certificate store type is *cstPFXFile*, this property must be set to the name of the file. When the type is *cstPFXBlob*, the property must be set to the binary contents of a PFX file (i.e., PKCS#12 certificate store).

 **StorePassword** *string*
Default: ""

If the type of certificate store requires a password, this field is used to specify the password needed to open the certificate store.

 **StoreType** *CertStoreTypes*
Default: 0

The type of certificate store for this certificate.

 The component supports both public and private keys in a variety of formats. When the *cstAuto* value is used, the component will automatically determine the type. This field can take one of the following values:

```csharp
sftp.SSHCert = new Certificate(CertStoreTypes.cstPKCS11,
                               @"C:\Program Files\OpenSC Project\OpenSC\pkcs11\opensc-pkcs11.dll",
                               "123456", // PIN
                               "CN=cert_subject");
sftp.SSHUser = "test";
sftp.SSHLogon("myhost", 22);
```

```csharp
certmgr.CertStoreType = CertStoreTypes.cstPKCS11;
certmgr.OnCertList += (s, e) => {
  secKeyBlob = e.CertEncoded;
};
certmgr.CertStore = @"C:\Program Files\OpenSC Project\OpenSC\pkcs11\opensc-pkcs11.dll";
certmgr.CertStorePassword = "123456"; // PIN
certmgr.ListStoreCertificates();

sftp.SSHCert = new Certificate(CertStoreTypes.cstPKCS11, secKeyBlob, "123456", "*");
sftp.SSHUser = "test";
sftp.SSHLogon("myhost", 22);
```

|  |  |
| --- | --- |
| 0 (cstUser - default) | For Windows, this specifies that the certificate store is a certificate store owned by the current user. NOTE: This store type is not available in Java. |
| 1 (cstMachine) | For Windows, this specifies that the certificate store is a machine store. NOTE: This store type is not available in Java. |
| 2 (cstPFXFile) | The certificate store is the name of a PFX (PKCS#12) file containing certificates. |
| 3 (cstPFXBlob) | The certificate store is a string (binary or Base64-encoded) representing a certificate store in PFX (PKCS#12) format. |
| 4 (cstJKSFile) | The certificate store is the name of a Java Key Store (JKS) file containing certificates. NOTE: This store type is only available in Java. |
| 5 (cstJKSBlob) | The certificate store is a string (binary or Base64-encoded) representing a certificate store in Java Key Store (JKS) format. NOTE: This store type is only available in Java. |
| 6 (cstPEMKeyFile) | The certificate store is the name of a PEM-encoded file that contains a private key and an optional certificate. |
| 7 (cstPEMKeyBlob) | The certificate store is a string (binary or Base64-encoded) that contains a private key and an optional certificate. |
| 8 (cstPublicKeyFile) | The certificate store is the name of a file that contains a PEM- or DER-encoded public key certificate. |
| 9 (cstPublicKeyBlob) | The certificate store is a string (binary or Base64-encoded) that contains a PEM- or DER-encoded public key certificate. |
| 10 (cstSSHPublicKeyBlob) | The certificate store is a string (binary or Base64-encoded) that contains an SSH-style public key. |
| 11 (cstP7BFile) | The certificate store is the name of a PKCS#7 file containing certificates. |
| 12 (cstP7BBlob) | The certificate store is a string (binary) representing a certificate store in PKCS#7 format. |
| 13 (cstSSHPublicKeyFile) | The certificate store is the name of a file that contains an SSH-style public key. |
| 14 (cstPPKFile) | The certificate store is the name of a file that contains a PPK (PuTTY Private Key). |
| 15 (cstPPKBlob) | The certificate store is a string (binary) that contains a PPK (PuTTY Private Key). |
| 16 (cstXMLFile) | The certificate store is the name of a file that contains a certificate in XML format. |
| 17 (cstXMLBlob) | The certificate store is a string that contains a certificate in XML format. |
| 18 (cstJWKFile) | The certificate store is the name of a file that contains a JWK (JSON Web Key). |
| 19 (cstJWKBlob) | The certificate store is a string that contains a JWK (JSON Web Key). |
| 21 (cstBCFKSFile) | The certificate store is the name of a file that contains a BCFKS (Bouncy Castle FIPS Key Store). NOTE: This store type is only available in Java and .NET. |
| 22 (cstBCFKSBlob) | The certificate store is a string (binary or Base64-encoded) representing a certificate store in BCFKS (Bouncy Castle FIPS Key Store) format. NOTE: This store type is only available in Java and .NET. |
| 23 (cstPKCS11) | The certificate is present on a physical security key accessible via a PKCS#11 interface. To use a security key, create a new [Certificate](#certificate-type) object and pass cstPKCS11 as the [StoreType](#Certificate_f_StoreType), the full path of the PKCS#11 DLL as the [Store](#Certificate_f_Store), and the PIN as the [StorePassword](#Certificate_f_StorePassword). Code Example. SSH Authentication with Security Key (without CertMgr): Alternatively, collect the necessary data using the [CertMgr](CertMgr.md#CertMgr) component by calling the [ListStoreCertificates](CertMgr.md#CertMgr_m_ListStoreCertificates) method after setting the corresponding properties accordingly. The certificate information returned in the [CertList](CertMgr.md#CertMgr_e_CertList) event's CertEncoded parameter may be saved for later use. When using a certificate obtained with this approach, pass the previously saved security key information as the [Store](#Certificate_f_Store) and set [StorePassword](#Certificate_f_StorePassword) to the PIN. Code Example. SSH Authentication with Security Key (with CertMgr): |
| 99 (cstAuto) | The store type is automatically detected from the input data. This setting may be used with both public and private keys and can detect any of the supported formats automatically. |

 **SubjectAltNames** *string (read-only)*
Default: ""

Comma-separated lists of alternative subject names for the certificate.

 **ThumbprintMD5** *string (read-only)*
Default: ""

The MD5 hash of the certificate. It is primarily used for X.509 certificates. If the hash does not already exist, it is automatically computed.

 **ThumbprintSHA1** *string (read-only)*
Default: ""

The SHA-1 hash of the certificate. It is primarily used for X.509 certificates. If the hash does not already exist, it is automatically computed.

 **ThumbprintSHA256** *string (read-only)*
Default: ""

The SHA-256 hash of the certificate. It is primarily used for X.509 certificates. If the hash does not already exist, it is automatically computed.

 **Usage** *string (read-only)*
Default: ""

The text description of [UsageFlags](#Certificate_f_UsageFlags).

This value will be one or more of the following strings and will be separated by commas:

- Digital Signature
- Non-Repudiation
- Key Encipherment
- Data Encipherment
- Key Agreement
- Certificate Signing
- CRL Signing
- Encipher Only

If the provider is OpenSSL, the value is a comma-separated list of X.509 certificate extension names.

 **UsageFlags** *int (read-only)*
Default: 0

The flags that show intended use for the certificate. The value of [UsageFlags](#Certificate_f_UsageFlags) is a combination of the following flags:

|  |  |
| --- | --- |
| 0x80 | Digital Signature |
| 0x40 | Non-Repudiation |
| 0x20 | Key Encipherment |
| 0x10 | Data Encipherment |
| 0x08 | Key Agreement |
| 0x04 | Certificate Signing |
| 0x02 | CRL Signing |
| 0x01 | Encipher Only |

Please see the [Usage](#Certificate_f_Usage) field for a text representation of [UsageFlags](#Certificate_f_UsageFlags).

This functionality currently is not available when the provider is OpenSSL.

 **Version** *string (read-only)*
Default: ""

The certificate's version number. The possible values are the strings "V1", "V2", and "V3".

 **Subject** *string*
Default: ""

The subject of the certificate used for client authentication.

This field will be populated with the full subject of the loaded certificate. When loading a certificate, the subject is used to locate the certificate in the store.

If an exact match is not found, the store is searched for subjects containing the value of the property.

If a match is still not found, the property is set to an empty string, and no certificate is selected.

The special value "*" picks a random certificate in the certificate store.

The certificate subject is a comma-separated list of distinguished name fields and values. For instance, "CN=www.server.com, OU=test, C=US, E=example@email.com". Common fields and their meanings are as follows:

| Field | Meaning |
| --- | --- |
| CN | Common Name. This is commonly a hostname like www.server.com. |
| O | Organization |
| OU | Organizational Unit |
| L | Locality |
| S | State |
| C | Country |
| E | Email Address |

If a field value contains a comma, it must be quoted.

 **Encoded** *string*
Default: ""

The certificate (PEM/Base64 encoded). This field is used to assign a specific certificate. The [Store](#Certificate_f_Store) and [Subject](#Certificate_f_Subject) fields also may be used to specify a certificate.

When [Encoded](#Certificate_f_Encoded) is set, a search is initiated in the current [Store](#Certificate_f_Store) for the private key of the certificate. If the key is found, [Subject](#Certificate_f_Subject) is updated to reflect the full subject of the selected certificate; otherwise, [Subject](#Certificate_f_Subject) is set to an empty string.

 **EncodedB** *byte []*
Default: ""

The certificate (PEM/Base64 encoded). This field is used to assign a specific certificate. The [Store](#Certificate_f_Store) and [Subject](#Certificate_f_Subject) fields also may be used to specify a certificate.

When [Encoded](#Certificate_f_Encoded) is set, a search is initiated in the current [Store](#Certificate_f_Store) for the private key of the certificate. If the key is found, [Subject](#Certificate_f_Subject) is updated to reflect the full subject of the selected certificate; otherwise, [Subject](#Certificate_f_Subject) is set to an empty string.

## Constructors

```text
public Certificate();
```

 Creates a instance whose properties can be set.

```text
public Certificate(string certificateFile);
```

 Opens * CertificateFile * and reads out the contents as an X.509 public key.

```text
public Certificate(byte[] encoded);
```

 Parses * Encoded * as an X.509 public key.

```text
public Certificate(CertStoreTypes storeType, string store, string storePassword, string subject);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a file containing the certificate store. * StorePassword * is the password used to protect the store.

 After the store has been successfully opened, the component will attempt to find the certificate identified by * Subject * . This can be either a complete or a substring match of the X.509 certificate's subject Distinguished Name (DN). The * Subject * parameter can also take an MD5, SHA-1, or SHA-256 thumbprint of the certificate to load in a "Thumbprint=value" format.

```text
public Certificate(CertStoreTypes storeType, string store, string storePassword, string subject, string configurationString);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a file containing the certificate store. * StorePassword * is the password used to protect the store.

 * ConfigurationString * is a newline-separated list of name-value pairs that may be used to modify the default behavior. Possible values include "PersistPFXKey", which shows whether or not the PFX key is persisted after performing operations with the private key. This correlates to the PKCS12_NO_PERSIST_KEY CryptoAPI option. The default value is True (the key is persisted). "Thumbprint" - an MD5, SHA-1, or SHA-256 thumbprint of the certificate to load. When specified, this value is used to select the certificate in the store. This is applicable to the * cstUser * , * cstMachine * , * cstPublicKeyFile * , and * cstPFXFile * store types. "UseInternalSecurityAPI" shows whether the platform (default) or the internal security API is used when performing certificate-related operations.

 After the store has been successfully opened, the component will attempt to find the certificate identified by * Subject * . This can be either a complete or a substring match of the X.509 certificate's subject Distinguished Name (DN). The * Subject * parameter can also take an MD5, SHA-1, or SHA-256 thumbprint of the certificate to load in a "Thumbprint=value" format.

```text
public Certificate(CertStoreTypes storeType, string store, string storePassword, byte[] encoded);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a file containing the certificate store. * StorePassword * is the password used to protect the store.

 After the store has been successfully opened, the component will load * Encoded * as an X.509 certificate and search the opened store for a corresponding private key.

```text
public Certificate(CertStoreTypes storeType, byte[] store, string storePassword, string subject);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a byte array containing the certificate data. * StorePassword * is the password used to protect the store.

 After the store has been successfully opened, the component will attempt to find the certificate identified by * Subject * . This can be either a complete or a substring match of the X.509 certificate's subject Distinguished Name (DN). The * Subject * parameter can also take an MD5, SHA-1, or SHA-256 thumbprint of the certificate to load in a "Thumbprint=value" format.

```text
public Certificate(CertStoreTypes storeType, byte[] store, string storePassword, string subject, string configurationString);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a byte array containing the certificate data. * StorePassword * is the password used to protect the store.

 After the store has been successfully opened, the component will attempt to find the certificate identified by * Subject * . This can be either a complete or a substring match of the X.509 certificate's subject Distinguished Name (DN). The * Subject * parameter can also take an MD5, SHA-1, or SHA-256 thumbprint of the certificate to load in a "Thumbprint=value" format.

```text
public Certificate(CertStoreTypes storeType, byte[] store, string storePassword, byte[] encoded);
```

 * StoreType * identifies the type of certificate store to use. See for descriptions of the different certificate stores. * Store * is a byte array containing the certificate data. * StorePassword * is the password used to protect the store.

 After the store has been successfully opened, the component will load * Encoded * as an X.509 certificate and search the opened store for a corresponding private key.

# Firewall Type

The firewall the component will connect through.

## Remarks

When connecting through a firewall, this type is used to specify different properties of the firewall, such as the firewall [Host](#Firewall_f_Host) and the [FirewallType](#Firewall_f_FirewallType).

The following fields are available:

- [AutoDetect](#Firewall_f_AutoDetect)

- [FirewallType](#Firewall_f_FirewallType)

- [Host](#Firewall_f_Host)

- [Password](#Firewall_f_Password)

- [Port](#Firewall_f_Port)

- [User](#Firewall_f_User)

## Fields

 **AutoDetect** *bool*
Default: False

Whether to automatically detect and use firewall system settings, if available.

 **FirewallType** *FirewallTypes*
Default: 0

The type of firewall to connect through. The applicable values are as follows:

|  |  |
| --- | --- |
| fwNone (0) | No firewall (default setting). |
| fwTunnel (1) | Connect through a tunneling proxy. [Port](#Firewall_f_Port) is set to 80. |
| fwSOCKS4 (2) | Connect through a SOCKS4 Proxy. [Port](#Firewall_f_Port) is set to 1080. |
| fwSOCKS5 (3) | Connect through a SOCKS5 Proxy. [Port](#Firewall_f_Port) is set to 1080. |
| fwSOCKS4A (10) | Connect through a SOCKS4A Proxy. [Port](#Firewall_f_Port) is set to 1080. |

 **Host** *string*
Default: ""

The name or IP address of the firewall (optional). If a [Host](#Firewall_f_Host) is given, the requested connections will be authenticated through the specified firewall when connecting.

If this field is set to a Domain Name, a DNS request is initiated. Upon successful termination of the request, this field is set to the corresponding address. If the search is not successful, the component throws an exception.

 **Password** *string*
Default: ""

A password if authentication is to be used when connecting through the firewall. If [Host](#Firewall_f_Host) is specified, the [User](#Firewall_f_User) and [Password](#Firewall_f_Password) fields are used to connect and authenticate to the given firewall. If the authentication fails, the component throws an exception.

 **Port** *int*
Default: 0

The Transmission Control Protocol (TCP) port for the firewall [Host](#Firewall_f_Host). See the description of the [Host](#Firewall_f_Host) field for details.

NOTE: This field is set automatically when [FirewallType](#Firewall_f_FirewallType) is set to a valid value. See the description of the [FirewallType](#Firewall_f_FirewallType) field for details.

 **User** *string*
Default: ""

A username if authentication is to be used when connecting through a firewall. If [Host](#Firewall_f_Host) is specified, this field and the [Password](#Firewall_f_Password) field are used to connect and authenticate to the given [Firewall](#firewall-type). If the authentication fails, the component throws an exception.

## Constructors

```text
public Firewall();
```

# Config Settings ([OFTPClient](#oftpclient-component) Component)

 The component accepts one or more of the following *configuration settings*. Configuration settings are similar in functionality to properties, but they are rarely used. In order to avoid "polluting" the property namespace of the component, access to these *internal properties* is provided through the [Config](#config-method-oftpclient-component) method.

### OFTPClient Config Settings

**AcceptAnySFIDCode**: Indicates that all SFID codes are acceptable.This setting controls whether the component checks the SFID codes when receiving files. When set to False (Default) and a file is received the component will check the client and server SFID codes sent by the server against the values specified in [ClientSFIDCode](#clientsfidcode-property-oftpclient-component) and [ServerSFIDCode](#serversfidcode-property-oftpclient-component). If they do not match an error is returned. In some situations it is necessary to consider any SFID code valid. To disable checking the SFID codes sent by the server set this to True.

**AllowRetry**: Whether to send a retry indicator when rejecting a file.When the server sends a file and it is rejected for any reason, if this setting is set to True the component will send a retry indicator value to the server to specify the file may be retried later.

When set to False (default) the component will send a value indicating the server should not retry the send operation.

**CertificateType**: Specifies the type of certificate being supplied.By default the component will use the certificate set in the [Certificate](#certificate-property-oftpclient-component) property for all operations that require a certificate. This setting allows for different certificates to be set for specific operations. First, specify the CertificateType via this setting and then set the [Certificate](#certificate-property-oftpclient-component) property. For instance:

```text
component.Config("CertificateType=3");
component.Certificate = mySigningCertificate;
```

 Possible values are:

|  |  |
| --- | --- |
| 0 (default) | All Operations |
| 1 | Session Authentication |
| 2 | Decryption |
| 3 | Signing |
| 4 | Receipt Signing |

**ConnectionType**: Specifies the type of connection that will be created.Use the [ConnectionType](#ConnectionType) setting to tell the component which type of connection to create. The default value is 0 (Both) in which the component can both send and receive files. However you can limit the component to only be able to send or receive files by specifying a value of 1 (Send Only) or 2 (Receive Only). Valid values are:

|  |  |
| --- | --- |
| 0 | Both (Default) |
| 1 | Send Only |
| 2 | Receive Only |

**CreditCount**: Specifies the credit value.This setting defines the maximum credit value to be sent in the initial connection (SSID command). The default value is 99 and the maximum value is 999. When connecting, the server will also indicate the value it wishes to use for the credit count. The smaller of the two values will be used. This setting may be queried after connecting to determine the negotiated value.

**DeleteOnError**: Whether received files are deleted when there is an error during processing.By default this value is True. When set to False and receiving a file, if the file is encrypted, signed, or compressed the file will be decrypted, verified, or decompressed. If there is an error during processing the original unprocessed file will be placed in [DownloadDirectory](#downloaddirectory-property-oftpclient-component). In that case you may choose what to do with the file based on the error reported during processing.

When this is set to True (default) and there is an error during processing the original unprocessed file will be deleted and no files will be placed in [DownloadDirectory](#downloaddirectory-property-oftpclient-component).

**DisconnectAfterEndSession**: Determines if the connection is closed immediately after ending the session.By default when [Logoff](#logoff-method-oftpclient-component) is called the component will close the TCP connection after ending the session (the ESID command is sent). To let the other side close the connection after it has received the end session command (ESID), set this to False.

**EnforceProtocolVersion**: Requires the server to support the same OFTP version.This settings controls the behavior when the server's OFTP version is different from the requested version. During the logon process the component will supply its OFTP [Version](#version-property-oftpclient-component) to the server. The server will respond with the OFTP version it is using for the connection. If the version is not the same, the action of the component depends on this setting.

When set to True, if the server's OFTP version does not match the client's [Version](#version-property-oftpclient-component), the component throws an exception. When set to False (default), if the server's OFTP version does not match the client's [Version](#version-property-oftpclient-component), the component will use the lowest mutually supported version.

**ExchangeBufferSize**: Specifies the data exchange buffer size in bytes.This setting defines the data exchange buffer size to be sent in the initial connection (SSID command) in bytes. The default value is 2048. When connecting, the server will also indicate the value it wishes to use for the data exchange buffer size. The smaller of the two values will be used. This setting may be queried after connecting to determine the negotiated value.

**ExchangeCertStoreType**: Specifies the store type when loading a certificate to be exchanged.This specifies the certificate store type when loading a certificate that will be sent to the remote party. This is only applicable when calling [ExchangeCertificate](#exchangecertificate-method-oftpclient-component). The default value is "8" which indicates the certificate will be loaded from a file on disk. When the certificate is not in a .cer format or is located in the Windows certificate store this setting should be set to the appropriate value before calling [ExchangeCertificate](#exchangecertificate-method-oftpclient-component).

For a list of possible values please see [StoreType](#Certificate_f_StoreType). Also see [ExchangeCertSubject](#ExchangeCertSubject).

**ExchangeCertSubject**: The subject of the certificate being exchanged.This specifies the subject of the certificate being exchanged. This will be used to load the appropriate certificate when [ExchangeCertificate](#exchangecertificate-method-oftpclient-component) is called. This is used in conjunction with [ExchangeCertStoreType](#ExchangeCertStoreType) and is only necessary when loading a certificate from a store that may hold more than one certificate (such as a Windows certificate store).

**FailOnUntrustedCert**: Whether or not to throw an exception when untrusted certificates are used.When [TrustedCerts](#trustedcerts-property-oftpclient-component) is populated the component will validate that loaded certificates were issued by a trusted CA in [TrustedCerts](#trustedcerts-property-oftpclient-component). This setting controls the behavior when an untrusted certificate is found. By default this value is True and the component will throw an exception. If this is set to False the component will fire the [Error](#error-event-oftpclient-component) event but the error will not be fatal and the operation will be allowed to continue.

**FileDescription**: Additional description information sent with the file.When sending a file this setting may be set to specify additional information. There is no restriction on the type of data supplied here. It may be set to a longer filename, or simply additional text data that you wish to pass to the receiver. The data supplied will be UTF-8 encoded by the component. The maximum length is 999 bytes (after UTF-8 encoding).

**FileHashAlgorithm**: The hash algorithm to use when sending a file.The file hash algorithm specified in this setting is used to calculate the hash sent along with an outgoing file. Possible values are:

|  |  |
| --- | --- |
| 0 | sha1 |
| 1 | sha256 (Default) |
| 2 | sha512 |

**FireEndResponseOnSend**: Determines if the EndResponse event is fired for outgoing EERP and NERPs.If set to True (default) the component will fire the [EndResponse](#endresponse-event-oftpclient-component) event for both sent and received end responses. If set to False the [EndResponse](#endresponse-event-oftpclient-component) event will fire only for received (incoming) end responses. The *Direction* parameter of [EndResponse](#endresponse-event-oftpclient-component) determines if the end response is being sent or received. The default value is True.

**FollowRedirects**: Determines behavior when importing trusted certificates and a HTTP redirect is returned.When [TrustedCertsData](#TrustedCertsData) holds a URL and [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) is called the component makes a HTTP request to obtain the trusted certificates. If the server returns a HTTP redirect this setting specifies how the component will handle it. Possible values are:

|  |  |
| --- | --- |
| 0 (default) | Never follow redirects. An exception will be thrown. |
| 1 | Always follow redirects. The redirect will be automatically followed. |
| 2 | Follow same scheme redirects. Follow the redirect if it matches the same scheme (http:// or https://). |

**FriendlyLogFormat**: Determines if a more friendly format is applied to PITrail event out.This setting effects the content of the Data parameter of the [PITrail](#pitrail-event-oftpclient-component) event. By default this setting is true and a format designed to be more easily read is used. If set to false the Data parameter will hold the raw unformatted protocol level content.

**LogLevel**: The level of information to log.This setting specifies the level of detail that is logged to the [Log](#log-event-oftpclient-component) event. Possible values are:

|  |  |
| --- | --- |
| 0 (None) | No messages are logged. |
| 1 (Info - Default) | Informational events such as OFTP commands which are sent and received. |
| 2 (Verbose) | Detailed data such as individual packet information is logged. |
| 3 (Debug) | Debug data including all relevant sent and received bytes are logged. |

**MaskSensitiveData**: Masks passwords in logs.The default value is True. When set to True, the component will mask passwords that otherwise would appear in its logs.

**ReceiptHashAlgorithm**: The receipt hash algorithm to request when sending a file.The receipt hash algorithm specified in this setting is sent to the receiving party when a file is sent, and the receiving party should use this value when calculating the hash returned in the EERP or NERP receipt. Possible values are:

|  |  |
| --- | --- |
| 0 | sha1 (Default) |
| 1 | sha256 |
| 2 | sha512 |

**ReceivedFileDateTime**: The datetime of the file being received.This setting may be queried to obtain the datetime of the received file.

**ReceivedFileDescription**: Additional description information received with the file.Query this setting after receiving a file to obtain any additional information provided by the server. The data will be UTF-8 decoded by the component.

**ReceivedFileEncryptionAlg**: The encryption algorithm used for the file being received.This setting may be queried to obtain the encryption algorithm used for encryption of the file being received. The possible values are:

|  |  |
| --- | --- |
| 0 | 3DES (Triple Data Encryption Standard). |
| 1 | AES (Advanced Encryption Standard CBC mode with a 256-bit key). |

**ReceivedFileName**: Returns the name of the received file.This setting may be queried inside the [EndTransfer](#endtransfer-event-oftpclient-component) event to obtain the name of the received file on disk. This includes the full path to the file on disk.

**ReceivedFileNameFormat**: The name format of received files.This setting specifies the format used when determining the local filename of a received file. The use of macros is supported to provide flexibility. This setting may include one or more of the following values:

- %VirtualFileName%
- %VirtualFileDate%
- %Originator%
- %Destination%
- %UserData%
- %CurrentTime%
- %GUID%

 An example value is "%VirtualFileName%_%VirtualFileDate%_%Destination%". The default value is "%VirtualFileName%".

The '%VirtualFileDate%' macro also supports date formatting through the use of an optional DateTime format string. The format of the macro with the date format string included is:

- %VirtualFileDate:CustomFormat%

 For example: "%VirtualFileDate:yyyyMMddHHmmssffff%"

 The name format of received files.This setting specifies the format used when determining the local filename of a received file. The use of macros is supported to provide flexibility. This setting may include one or more of the following values:

- %VirtualFileName%
- %VirtualFileDate%
- %Originator%
- %Destination%
- %UserData%
- %CurrentTime%
- %GUID%

 An example value is "%VirtualFileName%_%VirtualFileDate%_%Destination%". The default value is "%VirtualFileName%".

The '%VirtualFileDate%' macro also supports date formatting through the use of an optional DateTime format string. The format of the macro with the date format string included is:

- %VirtualFileDate:CustomFormat%

 For example: "%VirtualFileDate:yyyyMMddHHmmssffff%"

**ReceivedFileNameFormat**: The name format of received files.This setting specifies the format used when determining the local filename of a received file. The use of macros is supported to provide flexibility. This setting may include one or more of the following values:

- %VirtualFileName%
- %VirtualFileDate%
- %Originator%
- %Destination%
- %UserData%
- %CurrentTime%
- %GUID%

 An example value is "%VirtualFileName%_%VirtualFileDate%_%Destination%". The default value is "%VirtualFileName%".

The '%VirtualFileDate%' macro also supports date formatting through the use of an optional DateTime format string. The format of the macro with the date format string included is:

- %VirtualFileDate:CustomFormat%

 For example: "%VirtualFileDate:yyyyMMddHHmmssffff%"

 The name format of received files.This setting specifies the format used when determining the local filename of a received file. The use of macros is supported to provide flexibility. This setting may include one or more of the following values:

- %VirtualFileName%
- %VirtualFileDate%
- %Originator%
- %Destination%
- %UserData%
- %CurrentTime%
- %GUID%

 An example value is "%VirtualFileName%_%VirtualFileDate%_%Destination%". The default value is "%VirtualFileName%".

The '%VirtualFileDate%' macro also supports date formatting through the use of an optional DateTime format string. The format of the macro with the date format string included is:

- %VirtualFileDate:CustomFormat%

 For example: "%VirtualFileDate:yyyyMMddHHmmssffff%"

**RecipientCertificateType**: Specifies the type of recipient certificate being supplied.By default the component will use the certificate set in the [RecipientCert](#recipientcert-property-oftpclient-component) property for all operations that require a certificate. This setting allows for different certificates to be set for specific operations. First, specify the RecipientCertificateType via this setting and then set the [RecipientCert](#recipientcert-property-oftpclient-component) property. For instance:

```text
component.Config("RecipientCertificateType=3");
component.RecipientCert = mySignatureVerificationCertificate;
```

 Possible values are:

|  |  |
| --- | --- |
| 0 (default) | All Operations |
| 1 | Session Authentication |
| 2 | Encryption |
| 3 | Signature Verification |
| 4 | Receipt Signature Verification |

**Retry**: Indicates whether the recipient allows the send to be retried.When sending files the recipient may reject the file for a number of reasons. The recipient may indicate that the operation can be re-attempted later. Query this setting after a send attempt was rejected to determine if the recipient allows retries. This setting will return either True or False.

**SendCDAfterEFPA**: Specifies whether a CD is always sent after receiving an EFPA.When sending a file the recipient will respond with an EFPA once the file is received. Within this response is an indicator which tells the sender whether to issue a CD (Change Direction) command. The indicator is read by the component and a CD command is sent if requested. If a CD is not requested then no CD is sent.

When set to True, this overrides the default behavior and will always send a CD command regardless of whether the indicator is set in the EFPA.

This should only be set if there is a specific reason to do so. In most cases it is not necessary.

**TempPath**: The path of a directory where temporary files will be created.Under certain conditions, the component will create temporary files before processing a file. The location of the temporary files is determined by this setting. Temporary files are created if any of the following conditions are true.

- [Compress](#compress-property-oftpclient-component) is true
- [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) is set to slEncrypted
- [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) is set to slSigned
- [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) is set to slEncryptedAndSigned

Note that [VirtualFileSecurityLevel](#virtualfilesecuritylevel-property-oftpclient-component) is only applicable when [Version](#version-property-oftpclient-component) is set to oftpVer20.

**TrustedCertsData**: Specifies the source to be used when importing trusted certificates.When [ImportTrustedCerts](#importtrustedcerts-method-oftpclient-component) is called it will attempt to import certificates from the location specified here. By default this is the URL provided by Odette (http://www.odette.org/TSL/TSL_OFTP2.XML). This is the live list of CA certificates hosted by Odette. This may also be set to an absolute file path to load certificates from an offline source, or a string value containing the trusted CA certificates.

**VirtualFileDateFormat**: The DateTime format of received files.This setting specifies the DateTime format used by the component when reporting the VirtualFileDate of received files. The default format is "MM/dd/yyyy HH:mm:ss".

When using OFTP v2.0 If the component is configured to respond to EERP and NERP messages asynchronously this should be set to the value "yyyyMMddHHmmssffff" or a similar format that includes the same level of accuracy. This is required to ensure that when calling [SendEndResponse](#sendendresponse-method-oftpclient-component) the value saved from within the [EndTransfer](#endtransfer-event-oftpclient-component) event has the necessary data when sending a response.

### Base Config Settings

**BuildInfo**: Information about the product's build.When queried, this setting will return a string containing information about the product's build.

**GUIAvailable**: Whether or not a message loop is available for processing events.In a GUI-based application, long-running blocking operations may cause the application to stop responding to input until the operation returns. The component will attempt to discover whether or not the application has a message loop and, if one is discovered, it will process events in that message loop during any such blocking operation.

In some non-GUI applications, an invalid message loop may be discovered that will result in errant behavior. In these cases, setting [GUIAvailable](#GUIAvailable) to *false* will ensure that the component does not attempt to process external events.

**LicenseInfo**: Information about the current license.When queried, this setting will return a string containing information about the license this instance of a component is using. It will return the following information:

- Product: The product the license is for.
- Product Key: The key the license was generated from.
- License Source: Where the license was found (e.g., RuntimeLicense, License File).
- License Type: The type of license installed (e.g., Royalty Free, Single Server).
- Last Valid Build: The last valid build number for which the license will work.

**MaskSensitiveData**: Whether sensitive data is masked in log messages.In certain circumstances it may be beneficial to mask sensitive data, like passwords, in log messages. Set this to *true* to mask sensitive data. The default is *true*.

**UseFIPSCompliantAPI**: Tells the component whether or not to use FIPS certified APIs.When set to *true*, the component will utilize the underlying operating system's certified APIs. Java editions, regardless of OS, utilize Bouncy Castle Federal Information Processing Standards (FIPS), while all other Windows editions make use of Microsoft security libraries.

FIPS mode can be enabled by setting the *UseFIPSCompliantAPI* configuration setting to *true*. This is a static setting that applies to all instances of all components of the toolkit within the process. It is recommended to enable or disable this setting once before the component has been used to establish a connection. Enabling FIPS while an instance of the component is active and connected may result in unexpected behavior.

For more details, please see the [FIPS 140-2 Compliance](https://www.nsoftware.com/kb/articles/fips.rst) article.

NOTE: This setting is applicable only on Windows.

NOTE: Enabling FIPS compliance requires a special license; please contact [sales@nsoftware.com](mailto:sales@nsoftware.com) for details.

**UseInternalSecurityAPI**: Whether or not to use the system security libraries or an internal implementation. When set to *false*, the component will use the system security libraries by default to perform cryptographic functions where applicable. In this case, calls to unmanaged code will be made. In certain environments, this is not desirable. To use a completely managed security implementation, set this setting to *true*.

Setting this configuration setting to *true* tells the component to use the internal implementation instead of using the system security libraries.

 On Windows, this setting is set to *false* by default. On Linux/macOS, this setting is set to *true* by default.

NOTE: This setting is static. The value set is applicable to all components used in the application.

When this value is set, the product's system dynamic link library (DLL) is no longer required as a reference, as all unmanaged code is stored in that file.

# Trappable Errors ([OFTPClient](#oftpclient-component) Component)

### OFTPClient Errors

|  |  |
| --- | --- |
| 671 | OFTP protocol error. |
| 672 | Server supplied an invalid SSID code. |
| 673 | Server supplied an invalid SFID code. |
| 674 | Server supplied an invalid password. |
| 675 | Server returned an invalid client SSID code. |
| 676 | Server returned an invalid client SFID code. |
| 677 | Server returned an invalid client password. |
| 678 | "Error building packet to send." |
| 679 | Error reading files specified. |
| 680 | Invalid date timestamp. |
| 681 | Local file exists and overwrite is set to false. |
| 682 | Invalid hash value. |
| 683 | Invalid signature. |
| 684 | Cryptographic operation failed. |
| 685 | No encryption certificate was specified. |
| 686 | No signing certificate was specified. |
| 687 | Send failed. Check the description for more details. |
| 688 | The requested feature is only supported in OFTP Version 2.0. Check the description for more details. |
| 689 | A required certificate was not provided. The error descriptions indicates which property must be set. |
| 690 | Invalid Certificate. |
| 691 | Failed to import trusted certificates. |

### TCPClient Errors

|  |  |
| --- | --- |
| 100 | You cannot change the [RemotePort](#remoteport-property-oftpclient-component) at this time. A connection is in progress. |
| 101 | You cannot change the [RemoteHost](#remotehost-property-oftpclient-component) (Server) at this time. A connection is in progress. |
| 102 | The [RemoteHost](#remotehost-property-oftpclient-component) address is invalid (0.0.0.0). |
| 104 | Already connected. If you want to reconnect, close the current connection first. |
| 106 | You cannot change the LocalPort at this time. A connection is in progress. |
| 107 | You cannot change the [LocalHost](#localhost-property-oftpclient-component) at this time. A connection is in progress. |
| 112 | You cannot change [MaxLineLength](#MaxLineLength) at this time. A connection is in progress. |
| 116 | [RemotePort](#remoteport-property-oftpclient-component) cannot be zero. Please specify a valid service port number. |
| 117 | You cannot change the UseConnection option while the component is active. |
| 135 | Operation would block. |
| 201 | Timeout. |
| 211 | Action impossible in control's present state. |
| 212 | Action impossible while not connected. |
| 213 | Action impossible while listening. |
| 301 | Timeout. |
| 303 | Could not open file. |
| 434 | Unable to convert string to selected CodePage. |
| 1105 | Already connecting. If you want to reconnect, close the current connection first. |
| 1117 | You need to connect first. |
| 1119 | You cannot change the LocalHost at this time. A connection is in progress. |
| 1120 | Connection dropped by remote host. |

### TCP/IP Errors

|  |  |
| --- | --- |
| 10004 | [10004] Interrupted system call. |
| 10009 | [10009] Bad file number. |
| 10013 | [10013] Access denied. |
| 10014 | [10014] Bad address. |
| 10022 | [10022] Invalid argument. |
| 10024 | [10024] Too many open files. |
| 10035 | [10035] Operation would block. |
| 10036 | [10036] Operation now in progress. |
| 10037 | [10037] Operation already in progress. |
| 10038 | [10038] Socket operation on nonsocket. |
| 10039 | [10039] Destination address required. |
| 10040 | [10040] Message is too long. |
| 10041 | [10041] Protocol wrong type for socket. |
| 10042 | [10042] Bad protocol option. |
| 10043 | [10043] Protocol is not supported. |
| 10044 | [10044] Socket type is not supported. |
| 10045 | [10045] Operation is not supported on socket. |
| 10046 | [10046] Protocol family is not supported. |
| 10047 | [10047] Address family is not supported by protocol family. |
| 10048 | [10048] Address already in use. |
| 10049 | [10049] Cannot assign requested address. |
| 10050 | [10050] Network is down. |
| 10051 | [10051] Network is unreachable. |
| 10052 | [10052] Net dropped connection or reset. |
| 10053 | [10053] Software caused connection abort. |
| 10054 | [10054] Connection reset by peer. |
| 10055 | [10055] No buffer space available. |
| 10056 | [10056] Socket is already connected. |
| 10057 | [10057] Socket is not connected. |
| 10058 | [10058] Cannot send after socket shutdown. |
| 10059 | [10059] Too many references, cannot splice. |
| 10060 | [10060] Connection timed out. |
| 10061 | [10061] Connection refused. |
| 10062 | [10062] Too many levels of symbolic links. |
| 10063 | [10063] File name is too long. |
| 10064 | [10064] Host is down. |
| 10065 | [10065] No route to host. |
| 10066 | [10066] Directory is not empty |
| 10067 | [10067] Too many processes. |
| 10068 | [10068] Too many users. |
| 10069 | [10069] Disc Quota Exceeded. |
| 10070 | [10070] Stale NFS file handle. |
| 10071 | [10071] Too many levels of remote in path. |
| 10091 | [10091] Network subsystem is unavailable. |
| 10092 | [10092] WINSOCK DLL Version out of range. |
| 10093 | [10093] Winsock is not loaded yet. |
| 11001 | [11001] Host not found. |
| 11002 | [11002] Nonauthoritative 'Host not found' (try again or check DNS setup). |
| 11003 | [11003] Nonrecoverable errors: FORMERR, REFUSED, NOTIMP. |
| 11004 | [11004] Valid name, no data record (check DNS setup). |
