SQL Server
SQL Server
Examine SSL/TLS Server Certificate
See more Socket/SSL/TLS Examples
Demonstrates how an application can examine and check a server's SSL/TLS certificate.Chilkat SQL Server Downloads
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
DECLARE @hr int
DECLARE @iTmp0 int
-- Important: Do not use nvarchar(max). See the warning about using nvarchar(max).
DECLARE @sTmp0 nvarchar(4000)
DECLARE @success int
SELECT @success = 0
-- This example assumes the Chilkat API to have been previously unlocked.
-- See Global Unlock Sample for sample code.
DECLARE @socket int
EXEC @hr = sp_OACreate 'Chilkat.Socket', @socket OUT
IF @hr <> 0
BEGIN
PRINT 'Failed to create ActiveX component'
RETURN
END
-- Connect to a server.
DECLARE @useTls int
SELECT @useTls = 1
DECLARE @maxWaitMs int
SELECT @maxWaitMs = 2000
EXEC sp_OAMethod @socket, 'Connect', @success OUT, 'www.intel.com', 443, @useTls, @maxWaitMs
IF @success = 0
BEGIN
EXEC sp_OAGetProperty @socket, 'LastErrorText', @sTmp0 OUT
PRINT @sTmp0
EXEC @hr = sp_OADestroy @socket
RETURN
END
-- If we get here, the TLS connection ws made..
-- In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
-- Chilkat will keep it cached within the object that made the connection.
-- Get the server's cert and examine a few things.
DECLARE @cert int
EXEC @hr = sp_OACreate 'Chilkat.Cert', @cert OUT
EXEC sp_OAMethod @socket, 'GetServerCert', @success OUT, @cert
EXEC sp_OAGetProperty @cert, 'SubjectDN', @sTmp0 OUT
PRINT 'Distinguished Name: ' + @sTmp0
EXEC sp_OAGetProperty @cert, 'SubjectCN', @sTmp0 OUT
PRINT 'Common Name: ' + @sTmp0
EXEC sp_OAGetProperty @cert, 'IssuerDN', @sTmp0 OUT
PRINT 'Issuer Distinguished Name: ' + @sTmp0
EXEC sp_OAGetProperty @cert, 'IssuerCN', @sTmp0 OUT
PRINT 'Issuer Common Name: ' + @sTmp0
EXEC sp_OAGetProperty @cert, 'Expired', @iTmp0 OUT
PRINT 'Expired: ' + @iTmp0
EXEC sp_OAGetProperty @cert, 'Revoked', @iTmp0 OUT
PRINT 'Revoked: ' + @iTmp0
EXEC sp_OAGetProperty @cert, 'SignatureVerified', @iTmp0 OUT
PRINT 'Signature Verified: ' + @iTmp0
EXEC sp_OAGetProperty @cert, 'TrustedRoot', @iTmp0 OUT
PRINT 'Trusted Root: ' + @iTmp0
-- Sample output:
-- Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
-- Common Name: *.intel.com
-- Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
-- Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
-- Expired: False
-- Revoked: False
-- Signature Verified: True
-- Trusted Root: True
EXEC @hr = sp_OADestroy @socket
EXEC @hr = sp_OADestroy @cert
END
GO