Sample code for 30+ languages & platforms
Chilkat2-Python

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat Chilkat2-Python Downloads

Chilkat2-Python
import sys
import chilkat2

success = False

# This example assumes the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

socket = chilkat2.Socket()

# Connect to a server.
useTls = True
maxWaitMs = 2000
success = socket.Connect("www.intel.com",443,useTls,maxWaitMs)
if (success == False):
    print(socket.LastErrorText)
    sys.exit()

# If we get here, the TLS connection ws made..
# In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
# Chilkat will keep it cached within the object that made the connection.
# Get the server's cert and examine a few things.
cert = chilkat2.Cert()
socket.GetServerCert(cert)

print("Distinguished Name: " + cert.SubjectDN)
print("Common Name: " + cert.SubjectCN)
print("Issuer Distinguished Name: " + cert.IssuerDN)
print("Issuer Common Name: " + cert.IssuerCN)

print("Expired: " + str(cert.Expired))
print("Revoked: " + str(cert.Revoked))
print("Signature Verified: " + str(cert.SignatureVerified))
print("Trusted Root: " + str(cert.TrustedRoot))

# Sample output:

# Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
# Common Name: *.intel.com
# Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
# Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
# Expired: False
# Revoked: False
# Signature Verified: True
# Trusted Root: True