Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Examine Client Certificates for an Accepted TLS Connection

See more Socket/SSL/TLS Examples

Demonstrates how to access the client certificates for a TLS connection accepted by your application acting as the server.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final listenSslSocket = CkSocket();

  // An SSL/TLS server needs a digital certificate.  This example loads it from a PFX file.
  // This is the server's certificate.

  final cert = CkCert();
  try {
    cert.loadPfxFile('qa_data/serverCert/myServerCert.pfx', 'pfx_password');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // To accept client client certificates in the TLS handshake,
  // we must indicate a list of acceptable client certificate root CA DN's
  // that are allowed.  (DN is an acronym for Distinguished Name.)
  // Call AddSslAcceptableClientCaDn once for each acceptable CA DN.
  // Here are a few examples so you can see the general format of a DN.
  listenSslSocket.addSslAcceptableClientCaDn('C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root');
  listenSslSocket.addSslAcceptableClientCaDn('O=Digital Signature Trust Co., CN=DST Root CA X3');

  // Initialize with our server's TLS certificate.
  try {
    listenSslSocket.initSslServer(cert);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Bind and listen on a port:
  final myPort = 8123;
  // Allow for a max of 5 queued connect requests.
  final backLog = 5;
  try {
    listenSslSocket.bindAndListen(myPort, backLog);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Accept the next incoming connection.
  final maxWaitMillisec = 20000;

  final clientSock = CkSocket();
  try {
    listenSslSocket.acceptNext(maxWaitMillisec, clientSock);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Examine the client certs chain.  The 1st cert will be the client certificate, and
  // the subsequent certs will be the certs in the chain of authentication.
  final numClientCerts = clientSock.numReceivedClientCerts;
  print('numClientCerts = $numClientCerts');

  final clientCert = CkCert();
  var i = 0;
  while (i < numClientCerts) {
    clientSock.getRcvdClientCert(i, clientCert);
    print(clientCert.subjectDN);
    i++;
  }

  // Close the connection with the client
  clientSock.close(1000);
}