Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Validate Certificate using OCSP Protocol

See more Certificates Examples

Demonstrates how to validate a certificate (check the revoked status) using the OCSP protocol.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // This example will check the revoked status of a certificate loaded from a file.
  final cert = CkCert();
  try {
    cert.loadFromFile('qa_data/certs/google.crt');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Get the cert's OCSP URL.
  final ocspUrl = cert.ocspUrl;

  // Build the JSON that will be the OCSP request.

  // Possible hash algorithms are sha1, sha256, sha384, sha512.  
  final hashAlg = 'sha256';
  final prng = CkPrng();
  final json = CkJsonObject();
  json.emitCompact = false;
  // Read more about OCSP nonce lengths
  json.updateString('extensions.ocspNonce', prng.genRandom(16, 'base64'));
  json.i = 0;
  json.updateString('request[i].cert.hashAlg', hashAlg);
  json.updateString('request[i].cert.issuerNameHash', cert.hashOf('IssuerDN', hashAlg, 'base64'));
  json.updateString('request[i].cert.issuerKeyHash', cert.hashOf('IssuerPublicKey', hashAlg, 'base64'));
  json.updateString('request[i].cert.serialNumber', cert.serialNumber);

  print(json.emit());

  // Our OCSP request looks something like this:
  // {
  //   "extensions": {
  //     "ocspNonce": "qZDfbpO+nUxRzz6c/SPjE5QCAsPfpkQlRDxTnGl0gnxt7iXO"
  //   },
  //   "request": [
  //     {
  //       "cert": {
  //         "hashAlg": "sha1",
  //         "issuerNameHash": "9u2wY2IygZo19o11oJ0CShGqbK0=",
  //         "issuerKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
  //         "serialNumber": "6175535D87BF94B6"
  //       }
  //     }
  //   ]
  // }

  final ocspRequest = CkBinData();
  final http = CkHttp();

  // Convert our JSON to a binary (ASN.1) OCSP request
  try {
    http.createOcspRequest(json, ocspRequest);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Send the OCSP request to the OCSP server
  final resp = CkHttpResponse();
  try {
    http.httpBd('POST', ocspUrl, ocspRequest, 'application/ocsp-request', resp);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Get the binary (ASN.1) OCSP reply
  final ocspReply = CkBinData();
  resp.getBodyBd(ocspReply);

  // Convert the binary reply to JSON.
  // Also returns the overall OCSP response status.
  final jsonReply = CkJsonObject();
  final ocspStatus = http.parseOcspReply(ocspReply, jsonReply);

  // The ocspStatus can have one of these values:
  // -1:  The ARG1 does not contain a valid OCSP reply.
  // 0:  Successful - Response has valid confirmations..
  // 1: Malformed request - Illegal confirmation request.
  // 2: Internal error - Internal error in issuer.
  // 3: Try later -  Try again later.
  // 4: Not used - This value is never returned.
  // 5: Sig required - Must sign the request.
  // 6: Unauthorized - Request unauthorized.

  if (ocspStatus < 0) {
    print('Invalid OCSP reply.');
    return;
  }

  print('Overall OCSP Response Status: $ocspStatus');

  // Let's examine the OCSP response (in JSON).
  jsonReply.emitCompact = false;
  print(jsonReply.emit());

  // The JSON reply looks like this:
  // (Use the online tool at https://tools.chilkat.io/jsonParse.cshtml
  // to generate JSON parsing code.)

  // {
  //   "responseStatus": 0,
  //   "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
  //   "responseTypeName": "ocspBasic",
  //   "response": {
  //     "responderIdChoice": "KeyHash",
  //     "responderKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
  //     "dateTime": "20180803193937Z",
  //     "cert": [
  //       {
  //         "hashOid": "1.3.14.3.2.26",
  //         "hashAlg": "SHA-1",
  //         "issuerNameHash": "9u2wY2IygZo19o11oJ0CShGqbK0=",
  //         "issuerKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
  //         "serialNumber": "6175535D87BF94B6",
  //         "status": 0,
  //         "thisUpdate": "20180803193937Z",
  //         "nextUpdate": "20180810193937Z"
  //       }
  //     ]
  //   }
  // }
  // 

  // The certificate status:
  var certStatus = -1;
  if (jsonReply.hasMember('response.cert[0].status')) {
    certStatus = jsonReply.intOf('response.cert[0].status');
  }

  // Possible certStatus values are:
  // -1: No status returned.
  // 0: Good
  // 1: Revoked
  // 2: Unknown.
  print('Certificate Status: $certStatus');
}