Sample code for 30+ languages & platforms
Zig

Find Certificate by Email Address

See more Cert Store Examples

Demonstrates how to find a certificate having the specified email address either within the cert's subject email, or the RFC822 name.

In an X.509 certificate, an email address can typically be located in two places:

  1. RFC822 Name (Subject Alternative Name extension) -
    • The certificate may include an email address in the Subject Alternative Name (SAN) extension under the RFC822 Name field. This is a modern and preferred method because it allows for flexibility and alignment with security best practices.
    • To find it, Chilkat inspects the SAN extension in the certificate details.
  2. Subject (Common Name or Email Address attribute) -
    • Older certificates may store the email address directly in the Subject field, typically under the Email Address attribute ("emailAddress") or, less commonly, the Common Name (CN).
    • This method is less preferred in modern standards but can still be encountered in legacy implementations. Chilkat also searches here for the email address.

Note: Requires Chilkat v10.1.2 or later.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const cert_store = try chilkat.CertStore.init();
    defer cert_store.deinit();

    // This opens the Current User certificate store on Windows,
    // On MacOS and iOS it opens the default Keychain.
    const read_only = false;
    cert_store.openCurrentUserStore(read_only) catch {
        std.debug.print("{s}\n", .{try cert_store.getLastErrorText(alloc)});
        return;
    };

    // Find the certificate having the specified email address in either the RFC822 Name or in the Subject.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    const email_address = "joe@example.com";
    json.updateString("email", email_address) catch {};

    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    if (cert_store.findCert(json, cert)) {
        // Show the full distinguished name of the certificate.
        std.debug.print("Found: {s}\n", .{try cert.getSubjectDN(alloc)});
    } else |_| {
        std.debug.print("Not found.\n", .{});
    }
}