Sample code for 30+ languages & platforms
Swift

Get Certificate CRL Distribution Points

See more Certificates Examples

Demonstrates how to get a certificate's CRL Distribution Points extension data (assuming it exists). In the vast majority of cases, there will be one CRL Distribution Point.

Note: This example requires Chilkat v9.5.0.76 or greater.

Chilkat Swift Downloads

Swift

func chilkatTest() {
    var success: Bool = false

    let cert = CkoCert()!

    success = cert.load(fromFile: "qa_data/certs/test_haswdt.cer")
    if success != true {
        print("\(cert.lastErrorText!)")
        return
    }

    // Get the CRL Distribution Points extension, which is at OID 2.5.29.31
    var extensionXmlStr: String? = cert.getExtension(asXml: "2.5.29.31")
    if cert.lastMethodSuccess == false {
        print("Certificate does not have the CDP extension.")
        return
    }

    let xml = CkoXml()!
    xml.load(xmlData: extensionXmlStr)

    // See what we have..
    print("\(xml.getXml()!)")

    // We should get XML like this:

    // <?xml version="1.0" encoding="utf-8" ?>
    // <sequence>
    //     <sequence>
    //         <contextSpecific tag="0" constructed="1">
    //             <contextSpecific tag="0" constructed="1">
    //                 <contextSpecific tag="6" constructed="0">aHR0cDovL2NybC5jb21vZG9jYS5jb20vQ09NT0RPUlNBQ2xpZW50QXV0aGVudGljYXRpb25hbmRTZWN1
    // cmVFbWFpbENBLmNybA==</contextSpecific>
    //             </contextSpecific>
    //         </contextSpecific>
    //     </sequence>
    // </sequence>
    // 

    // Assuming there is one CRL Distribution Point...
    let sbDistPoint = CkoStringBuilder()!
    success = xml.getChildContentSb(tagPath: "sequence|contextSpecific|contextSpecific|contextSpecific", sb: sbDistPoint)
    if success == true {
        sbDistPoint.decode(encoding: "base64", charset: "utf-8")
        print("CRL Distribution Point:  \(sbDistPoint.getAsString()!)")
    }

    // Sample output:
    // CRL Distribution Point:  http://crl.comodoca.com/COMODORSAClientAuthenticationandSecureEmailCA.crl

}