Sample code for 30+ languages & platforms
Delphi DLL Requires Chilkat v11.0.0+

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat Delphi DLL Downloads

Delphi DLL
var
success: Boolean;
socket: HCkSocket;
useTls: Boolean;
maxWaitMs: Integer;
cert: HCkCert;

begin
success := False;

//  This example assumes the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

socket := CkSocket_Create();

//  Connect to a server.
useTls := True;
maxWaitMs := 2000;
success := CkSocket_Connect(socket,'www.intel.com',443,useTls,maxWaitMs);
if (success = False) then
  begin
    Memo1.Lines.Add(CkSocket__lastErrorText(socket));
    Exit;
  end;

//  If we get here, the TLS connection ws made..
//  In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
//  Chilkat will keep it cached within the object that made the connection.
//  Get the server's cert and examine a few things.
cert := CkCert_Create();
CkSocket_GetServerCert(socket,cert);

Memo1.Lines.Add('Distinguished Name: ' + CkCert__subjectDN(cert));
Memo1.Lines.Add('Common Name: ' + CkCert__subjectCN(cert));
Memo1.Lines.Add('Issuer Distinguished Name: ' + CkCert__issuerDN(cert));
Memo1.Lines.Add('Issuer Common Name: ' + CkCert__issuerCN(cert));

Memo1.Lines.Add('Expired: ' + IntToStr(Ord(CkCert_getExpired(cert))));
Memo1.Lines.Add('Revoked: ' + IntToStr(Ord(CkCert_getRevoked(cert))));
Memo1.Lines.Add('Signature Verified: ' + IntToStr(Ord(CkCert_getSignatureVerified(cert))));
Memo1.Lines.Add('Trusted Root: ' + IntToStr(Ord(CkCert_getTrustedRoot(cert))));

//  Sample output:

//  Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
//  Common Name: *.intel.com
//  Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
//  Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
//  Expired: False
//  Revoked: False
//  Signature Verified: True
//  Trusted Root: True

CkSocket_Dispose(socket);
CkCert_Dispose(cert);