Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Examine SSL/TLS Server Certificate

See more Socket/SSL/TLS Examples

Demonstrates how an application can examine and check a server's SSL/TLS certificate.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const socket = try chilkat.Socket.init();
    defer socket.deinit();

    // Connect to a server.
    const use_tls = true;
    const max_wait_ms = 2000;
    socket.connect("www.intel.com", 443, use_tls, max_wait_ms) catch {
        std.debug.print("{s}\n", .{try socket.getLastErrorText(alloc)});
        return;
    };

    // If we get here, the TLS connection ws made..
    // In any SSL/TLS handshake, the server sends its certificate in a TLS handshake message.
    // Chilkat will keep it cached within the object that made the connection.
    // Get the server's cert and examine a few things.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    socket.getServerCert(cert) catch {};

    std.debug.print("Distinguished Name: {s}\n", .{try cert.getSubjectDN(alloc)});
    std.debug.print("Common Name: {s}\n", .{try cert.getSubjectCN(alloc)});
    std.debug.print("Issuer Distinguished Name: {s}\n", .{try cert.getIssuerDN(alloc)});
    std.debug.print("Issuer Common Name: {s}\n", .{try cert.getIssuerCN(alloc)});

    std.debug.print("Expired: {}\n", .{cert.getExpired()});
    std.debug.print("Revoked: {}\n", .{cert.getRevoked()});
    std.debug.print("Signature Verified: {}\n", .{cert.getSignatureVerified()});
    std.debug.print("Trusted Root: {}\n", .{cert.getTrustedRoot()});

    // Sample output:

    // Distinguished Name: C=US, ST=California, O=Intel Corporation, CN=*.intel.com
    // Common Name: *.intel.com
    // Issuer Distinguished Name: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
    // Issuer Common Name: Sectigo RSA Organization Validation Secure Server CA
    // Expired: False
    // Revoked: False
    // Signature Verified: True
    // Trusted Root: True
}