SSL / TLS Backends

sgcWebSockets ships five interchangeable TLS transports behind a single property, TLSOptions.IOHandler. Choose OpenSSL for maximum portability, a native platform backend (Windows SChannel, Android, iOS/macOS) that uses the operating system's own TLS stack with no OpenSSL libraries to deploy, or the Native TLS engine, a TLS 1.3 and TLS 1.2 stack written in Object Pascal that carries no dependency on any target and negotiates post-quantum X25519MLKEM768 key exchange by default. On Windows, OpenSSL itself can also be linked statically into your executable, so you stay on OpenSSL with nothing to deploy either. Switching backend is one line of code, nothing else changes.

Five TLS Transports, One Property

Every backend plugs into the same TLSOptions API. Pick the one that fits your platform and deployment, then set TLSOptions.IOHandler.

Backend Comparison

Platforms, deployment footprint, TLS 1.3 support and edition for each transport.

Backend Platforms Library to deploy TLS 1.3 Edition
OpenSSL Windows, Linux, macOS, iOS, Android libssl/libcrypto, or none on Windows (static link) Yes All editions
SChannel Windows None (built into Windows) Yes (Windows 11/Server 2022+) Professional, Enterprise
Android TLS Android None (uses the OS) Yes Enterprise
Apple TLS iOS, macOS None (uses the OS) Yes (10.14+/iOS 12+) Enterprise
Native TLS Windows, Linux, macOS, iOS, Android None (pure Object Pascal) Yes (and TLS 1.2) Standard, Professional, Enterprise, or the sgcCrypto pack

Pick a Backend

Each transport has its own page with the full setup, code for Delphi and C++Builder, deployment notes and edition details.

OpenSSL (iohOpenSSL)

Cross-platform TLS over Indy's socket, available on every platform sgcWebSockets targets and the default on most. Full TLS 1.0 to 1.3, the broadest cipher coverage, custom CA, client certificates and ALPN. You deploy the OpenSSL runtime libraries with your app. Included in every edition. On Windows, it can also be linked statically into the executable instead, with nothing to deploy.

Read the full guide →

SChannel (iohSChannel)

Microsoft's native TLS stack (Secure Channel / SSPI), built into Windows. Zero library deployment, no OpenSSL DLLs to ship or patch, and it uses the Windows certificate store. Windows-only. Included in the Professional and Enterprise editions.

Read the full guide →

Native Android TLS (iohAndroidTLS)

Android-native TLS using the platform's SSLEngine through JNI. No OpenSSL .so in your APK, validation against the Android system trust store, TLS 1.3, and ALPN on Android 10 (API 29) and later. Enterprise edition.

Read the full guide →

Native Apple TLS (iohAppleTLS)

Apple-native TLS for iOS and macOS, with no OpenSSL .dylib to deploy. It auto-selects Network.framework (TLS 1.3) on macOS 10.14+ / iOS 12+ and falls back to Secure Transport (TLS 1.2) on older systems, with system trust, SNI, custom CA, client cert / mTLS and ALPN. Enterprise edition.

Read the full guide →

Native TLS (iohNativeTLS)

A TLS 1.3 and TLS 1.2 implementation written entirely in Object Pascal on top of the sgcCrypto units, so it deploys nothing at all, on Windows, Linux, macOS, iOS or Android. Set TLSOptions.IOHandler := iohNativeTLS on a client, or SSLOptions.IOHandler := iohNativeTLS on a server, the IOCP and EPOLL server engines included. TLSOptions.NativeTLS_Options.Groups and TLSOptions.NativeTLS_Options.CipherSuites take colon separated, OpenSSL style lists. They default to X25519MLKEM768:X25519:secp256r1:secp384r1 and TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256 plus the TLS 1.2 defaults, so a handshake against a peer that supports it is post-quantum hybrid with no configuration.

TLS 1.3 and TLS 1.2. TLSOptions.Version on a client, and SSLOptions.Version on a server, is the lowest version allowed: tls1_2 or tlsUndefined negotiates TLS 1.3 or TLS 1.2, and tls1_3 allows TLS 1.3 only. For TLS 1.2 only, list only TLS 1.2 suites in NativeTLS_Options.CipherSuites. TLS 1.2 offers ECDHE_ECDSA and ECDHE_RSA with AES-128-GCM, AES-256-GCM and ChaCha20-Poly1305 by default, while the ECDHE AES-CBC suites and the RSA key exchange are there only when you name them. It uses X25519, secp256r1 or secp384r1, because the hybrid post-quantum groups exist only in TLS 1.3. TLS 1.2 comes with the extended master secret of RFC 7627 and the RFC 8446 downgrade protection on both sides, and it refuses renegotiation and SHA-1 signatures.

What it does not do. The engine speaks TLS 1.3 and TLS 1.2 only, with no TLS 1.1, TLS 1.0 or SSL. There is no session resumption and no PSK, no 0-RTT and no QUIC. Trust roots come from TLSOptions.RootCertFile, plus the roots the operating system trusts when NativeTLS_Options.UseSystemRoots is True, read from the Windows ROOT store or a CA bundle file and never from the macOS or iOS keychain or the Android store, and the component event OnSSLVerifyPeer is not available for it, the engine has its own verification hooks. Stay on OpenSSL or a platform backend when you need any of those.

It is part of sgcCrypto, so it ships from the Standard edition up and in the standalone sgcCrypto pack.

Edition note

Native platform TLS, Android (iohAndroidTLS) and Apple (iohAppleTLS), requires the Enterprise edition. OpenSSL (iohOpenSSL) is included in every edition; SChannel (iohSChannel) is included in the Professional and Enterprise editions. Static linking OpenSSL on Windows also requires Enterprise or All-Access. Native TLS (iohNativeTLS) is part of sgcCrypto, so it ships from the Standard edition up, and in the standalone sgcCrypto pack.

Switch With One Line

All five backends share the same TLSOptions API, so moving between them is a single property change. Nothing else in your code has to change.

TLS & VerifyCertificate

Enable TLS and toggle peer certificate verification the same way on every backend.

RootCertFile

Point at a custom CA root to trust a private or self-signed certificate authority.

CertFile & Password

Supply a client certificate and its password for mutual TLS (mTLS) authentication.

ALPNProtocols

Advertise application protocols (for example http/1.1) during the TLS handshake.

// Same TLSOptions, only the IOHandler line changes per platform.
WSClient.TLS := True;
WSClient.TLSOptions.IOHandler := iohOpenSSL;   // or iohSChannel / iohAndroidTLS / iohAppleTLS / iohNativeTLS
WSClient.TLSOptions.VerifyCertificate := True;
WSClient.TLSOptions.RootCertFile := '';
WSClient.TLSOptions.CertFile := '';
WSClient.TLSOptions.Password := '';
WSClient.TLSOptions.ALPNProtocols.Add('http/1.1');
WSClient.Active := True;
// Same TLSOptions, only the IOHandler line changes per platform.
WSClient->TLS = true;
WSClient->TLSOptions->IOHandler = iohOpenSSL;   // or iohSChannel / iohAndroidTLS / iohAppleTLS / iohNativeTLS
WSClient->TLSOptions->VerifyCertificate = true;
WSClient->TLSOptions->RootCertFile = "";
WSClient->TLSOptions->CertFile = "";
WSClient->TLSOptions->Password = "";
WSClient->TLSOptions->ALPNProtocols->Add("http/1.1");
WSClient->Active = true;
Best value: All-AccessEvery eSeGeCe product, Premium Support included, from €1,059/year.
See All-Access pricing

Native TLS, Zero OpenSSL to Deploy

Download the free trial and switch TLS backends with a single line of code.