Sample code for 30+ languages & platforms
Objective-C

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat Objective-C Downloads

Objective-C
#import <CkoSocket.h>
#import <CkoCert.h>

BOOL success = NO;

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

CkoSocket *socket = [[CkoSocket alloc] init];

// Connect to a server.
BOOL useTls = YES;
int maxWaitMs = 2000;
success = [socket Connect: @"www.intel.com" port: [NSNumber numberWithInt: 443] ssl: useTls maxWaitMs: [NSNumber numberWithInt: maxWaitMs]];
if (success == NO) {
    NSLog(@"%@",socket.LastErrorText);
    return;
}

// If we get here, the TLS connection ws made..
// In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
// Chilkat will keep it cached within the object that made the connection.
// Get the server's cert and examine a few things.
CkoCert *cert = [[CkoCert alloc] init];
[socket GetServerCert: cert];

NSLog(@"%@%@",@"Distinguished Name: ",cert.SubjectDN);
NSLog(@"%@%@",@"Common Name: ",cert.SubjectCN);
NSLog(@"%@%@",@"Issuer Distinguished Name: ",cert.IssuerDN);
NSLog(@"%@%@",@"Issuer Common Name: ",cert.IssuerCN);

NSLog(@"%@%d",@"Expired: ",cert.Expired);
NSLog(@"%@%d",@"Revoked: ",cert.Revoked);
NSLog(@"%@%d",@"Signature Verified: ",cert.SignatureVerified);
NSLog(@"%@%d",@"Trusted Root: ",cert.TrustedRoot);

// Sample output:

// Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
// Common Name: *.intel.com
// Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
// Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
// Expired: False
// Revoked: False
// Signature Verified: True
// Trusted Root: True