Sample code for 30+ languages & platforms
Unicode C

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat Unicode C Downloads

Unicode C
#include <C_CkSocketW.h>
#include <C_CkCertW.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkSocketW socket;
    BOOL useTls;
    int maxWaitMs;
    HCkCertW cert;

    success = FALSE;

    //  This example assumes the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    socket = CkSocketW_Create();

    //  Connect to a server.
    useTls = TRUE;
    maxWaitMs = 2000;
    success = CkSocketW_Connect(socket,L"www.intel.com",443,useTls,maxWaitMs);
    if (success == FALSE) {
        wprintf(L"%s\n",CkSocketW_lastErrorText(socket));
        CkSocketW_Dispose(socket);
        return;
    }

    //  If we get here, the TLS connection ws made..
    //  In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
    //  Chilkat will keep it cached within the object that made the connection.
    //  Get the server's cert and examine a few things.
    cert = CkCertW_Create();
    CkSocketW_GetServerCert(socket,cert);

    wprintf(L"Distinguished Name: %s\n",CkCertW_subjectDN(cert));
    wprintf(L"Common Name: %s\n",CkCertW_subjectCN(cert));
    wprintf(L"Issuer Distinguished Name: %s\n",CkCertW_issuerDN(cert));
    wprintf(L"Issuer Common Name: %s\n",CkCertW_issuerCN(cert));

    wprintf(L"Expired: %d\n",CkCertW_getExpired(cert));
    wprintf(L"Revoked: %d\n",CkCertW_getRevoked(cert));
    wprintf(L"Signature Verified: %d\n",CkCertW_getSignatureVerified(cert));
    wprintf(L"Trusted Root: %d\n",CkCertW_getTrustedRoot(cert));

    //  Sample output:

    //  Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
    //  Common Name: *.intel.com
    //  Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
    //  Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
    //  Expired: False
    //  Revoked: False
    //  Signature Verified: True
    //  Trusted Root: True


    CkSocketW_Dispose(socket);
    CkCertW_Dispose(cert);

    }