Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Chilkat2-Python) Examine Client Certificates for an Accepted TLS ConnectionDemonstrates how to access the client certificates for a TLS connection accepted by your application acting as the server.
import sys import chilkat2 # This example requires the Chilkat API to have been previously unlocked. # See Global Unlock Sample for sample code. listenSslSocket = chilkat2.Socket() # An SSL/TLS server needs a digital certificate. This example loads it from a PFX file. # This is the server's certificate. cert = chilkat2.Cert() success = cert.LoadPfxFile("qa_data/serverCert/myServerCert.pfx","pfx_password") if (success != True): print(cert.LastErrorText) sys.exit() # To accept client client certificates in the TLS handshake, # we must indicate a list of acceptable client certificate root CA DN's # that are allowed. (DN is an acronym for Distinguished Name.) # Call AddSslAcceptableClientCaDn once for each acceptable CA DN. # Here are a few examples so you can see the general format of a DN. listenSslSocket.AddSslAcceptableClientCaDn("C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root") listenSslSocket.AddSslAcceptableClientCaDn("O=Digital Signature Trust Co., CN=DST Root CA X3") # Initialize with our server's TLS certificate. success = listenSslSocket.InitSslServer(cert) if (success != True): print(listenSslSocket.LastErrorText) sys.exit() # Bind and listen on a port: myPort = 8123 # Allow for a max of 5 queued connect requests. backLog = 5 success = listenSslSocket.BindAndListen(myPort,backLog) if (success != True): print(listenSslSocket.LastErrorText) sys.exit() # Accept the next incoming connection. maxWaitMillisec = 20000 # clientSock is a CkSocket clientSock = listenSslSocket.AcceptNextConnection(maxWaitMillisec) if (listenSslSocket.LastMethodSuccess == False): print(listenSslSocket.LastErrorText) sys.exit() # Examine the client certs chain. The 1st cert will be the client certificate, and # the subsequent certs will be the certs in the chain of authentication. numClientCerts = clientSock.NumReceivedClientCerts print("numClientCerts = " + str(numClientCerts)) i = 0 while i < numClientCerts : # clientCert is a CkCert clientCert = clientSock.GetReceivedClientCert(i) print(clientCert.SubjectDN) i = i + 1 # Close the connection with the client success = clientSock.Close(1000) |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.