Objective-C
Objective-C
Examine SSL/TLS Server Certificate
See more Socket/SSL/TLS Examples
Demonstrates how an application can examine and check a server's SSL/TLS certificate.Chilkat Objective-C Downloads
#import <CkoSocket.h>
#import <CkoCert.h>
BOOL success = NO;
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
CkoSocket *socket = [[CkoSocket alloc] init];
// Connect to a server.
BOOL useTls = YES;
int maxWaitMs = 2000;
success = [socket Connect: @"www.intel.com" port: [NSNumber numberWithInt: 443] ssl: useTls maxWaitMs: [NSNumber numberWithInt: maxWaitMs]];
if (success == NO) {
NSLog(@"%@",socket.LastErrorText);
return;
}
// If we get here, the TLS connection ws made..
// In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
// Chilkat will keep it cached within the object that made the connection.
// Get the server's cert and examine a few things.
CkoCert *cert = [[CkoCert alloc] init];
[socket GetServerCert: cert];
NSLog(@"%@%@",@"Distinguished Name: ",cert.SubjectDN);
NSLog(@"%@%@",@"Common Name: ",cert.SubjectCN);
NSLog(@"%@%@",@"Issuer Distinguished Name: ",cert.IssuerDN);
NSLog(@"%@%@",@"Issuer Common Name: ",cert.IssuerCN);
NSLog(@"%@%d",@"Expired: ",cert.Expired);
NSLog(@"%@%d",@"Revoked: ",cert.Revoked);
NSLog(@"%@%d",@"Signature Verified: ",cert.SignatureVerified);
NSLog(@"%@%d",@"Trusted Root: ",cert.TrustedRoot);
// Sample output:
// Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
// Common Name: *.intel.com
// Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
// Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
// Expired: False
// Revoked: False
// Signature Verified: True
// Trusted Root: True