Sample code for 30+ languages & platforms
SQL Server

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @iTmp0 int
    -- Important: Do not use nvarchar(max).  See the warning about using nvarchar(max).
    DECLARE @sTmp0 nvarchar(4000)
    DECLARE @success int
    SELECT @success = 0

    -- This example assumes the Chilkat API to have been previously unlocked.
    -- See Global Unlock Sample for sample code.

    DECLARE @socket int
    EXEC @hr = sp_OACreate 'Chilkat.Socket', @socket OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    -- Connect to a server.
    DECLARE @useTls int
    SELECT @useTls = 1
    DECLARE @maxWaitMs int
    SELECT @maxWaitMs = 2000
    EXEC sp_OAMethod @socket, 'Connect', @success OUT, 'www.intel.com', 443, @useTls, @maxWaitMs
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @socket, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @socket
        RETURN
      END

    -- If we get here, the TLS connection ws made..
    -- In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
    -- Chilkat will keep it cached within the object that made the connection.
    -- Get the server's cert and examine a few things.
    DECLARE @cert int
    EXEC @hr = sp_OACreate 'Chilkat.Cert', @cert OUT

    EXEC sp_OAMethod @socket, 'GetServerCert', @success OUT, @cert


    EXEC sp_OAGetProperty @cert, 'SubjectDN', @sTmp0 OUT
    PRINT 'Distinguished Name: ' + @sTmp0

    EXEC sp_OAGetProperty @cert, 'SubjectCN', @sTmp0 OUT
    PRINT 'Common Name: ' + @sTmp0

    EXEC sp_OAGetProperty @cert, 'IssuerDN', @sTmp0 OUT
    PRINT 'Issuer Distinguished Name: ' + @sTmp0

    EXEC sp_OAGetProperty @cert, 'IssuerCN', @sTmp0 OUT
    PRINT 'Issuer Common Name: ' + @sTmp0


    EXEC sp_OAGetProperty @cert, 'Expired', @iTmp0 OUT
    PRINT 'Expired: ' + @iTmp0

    EXEC sp_OAGetProperty @cert, 'Revoked', @iTmp0 OUT
    PRINT 'Revoked: ' + @iTmp0

    EXEC sp_OAGetProperty @cert, 'SignatureVerified', @iTmp0 OUT
    PRINT 'Signature Verified: ' + @iTmp0

    EXEC sp_OAGetProperty @cert, 'TrustedRoot', @iTmp0 OUT
    PRINT 'Trusted Root: ' + @iTmp0

    -- Sample output:

    -- Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
    -- Common Name: *.intel.com
    -- Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
    -- Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
    -- Expired: False
    -- Revoked: False
    -- Signature Verified: True
    -- Trusted Root: True

    EXEC @hr = sp_OADestroy @socket
    EXEC @hr = sp_OADestroy @cert


END
GO