Sample code for 30+ languages & platforms
C++

Enumerate Server-Advertised Acceptable Client CAs

See more Socket/SSL/TLS Examples

Demonstrates Socket.GetSslAcceptableClientCaDn, which returns a certificate-authority distinguished name advertised by a TLS server when it requests a client certificate.

Background. Valid indexes range from 0 through NumSslAcceptableClientCAs minus one. A client can use these names to select an appropriate client certificate.

Chilkat C++ Downloads

C++
#include <CkSocket.h>

void ChilkatSample(void)
    {
    bool success = false;

    CkSocket socket;

    //  Connect to the server using TLS.
    bool bTls = true;
    int maxWaitMs = 5000;
    success = socket.Connect("example.com",5000,bTls,maxWaitMs);
    if (success == false) {
        std::cout << socket.lastErrorText() << "\r\n";
        return;
    }

    //  After connecting to a server that requests a client certificate, enumerate the certificate-
    //  authority distinguished names the server advertised as acceptable.
    int numCAs = socket.get_NumSslAcceptableClientCAs();
    int i;
    for (i = 0; i <= numCAs - 1; i++) {
        const char *caDn = socket.getSslAcceptableClientCaDn(i);
        if (socket.get_LastMethodSuccess() == false) {
            std::cout << socket.lastErrorText() << "\r\n";
            return;
        }

        std::cout << caDn << "\r\n";
    }
    }