Sample code for 30+ languages & platforms
PowerShell

Enumerate Server-Advertised Acceptable Client CAs

See more Socket/SSL/TLS Examples

Demonstrates Socket.GetSslAcceptableClientCaDn, which returns a certificate-authority distinguished name advertised by a TLS server when it requests a client certificate.

Background. Valid indexes range from 0 through NumSslAcceptableClientCAs minus one. A client can use these names to select an appropriate client certificate.

Chilkat PowerShell Downloads

PowerShell
Add-Type -Path "C:\chilkat\ChilkatDotNet47-x64\ChilkatDotNet47.dll"

$success = $false

$socket = New-Object Chilkat.Socket

#  Connect to the server using TLS.
$bTls = $true
$maxWaitMs = 5000
$success = $socket.Connect("example.com",5000,$bTls,$maxWaitMs)
if ($success -eq $false) {
    $($socket.LastErrorText)
    exit
}

#  After connecting to a server that requests a client certificate, enumerate the certificate-
#  authority distinguished names the server advertised as acceptable.
$numCAs = $socket.NumSslAcceptableClientCAs

for ($i = 0; $i -le $numCAs - 1; $i++) {
    $caDn = $socket.GetSslAcceptableClientCaDn($i)
    if ($socket.LastMethodSuccess -eq $false) {
        $($socket.LastErrorText)
        exit
    }

    $($caDn)
}