Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Validate Certificate using OCSP Protocol

See more Certificates Examples

Demonstrates how to validate a certificate (check the revoked status) using the OCSP protocol.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // This example will check the revoked status of a certificate loaded from a file.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadFromFile("qa_data/certs/google.crt") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Get the cert's OCSP URL.
    const ocsp_url = try cert.getOcspUrl(alloc);

    // Build the JSON that will be the OCSP request.

    // Possible hash algorithms are sha1, sha256, sha384, sha512.
    const hash_alg = "sha256";
    const prng = try chilkat.Prng.init();
    defer prng.deinit();
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.setEmitCompact(false);
    // Read more about OCSP nonce lengths
    json.updateString("extensions.ocspNonce", try prng.genRandom(alloc, 16, "base64")) catch {};
    json.setI(0);
    json.updateString("request[i].cert.hashAlg", hash_alg) catch {};
    json.updateString("request[i].cert.issuerNameHash", try cert.hashOf(alloc, "IssuerDN", hash_alg, "base64")) catch {};
    json.updateString("request[i].cert.issuerKeyHash", try cert.hashOf(alloc, "IssuerPublicKey", hash_alg, "base64")) catch {};
    json.updateString("request[i].cert.serialNumber", try cert.getSerialNumber(alloc)) catch {};

    std.debug.print("{s}\n", .{try json.emit(alloc)});

    // Our OCSP request looks something like this:
    // {
    //   "extensions": {
    //     "ocspNonce": "qZDfbpO+nUxRzz6c/SPjE5QCAsPfpkQlRDxTnGl0gnxt7iXO"
    //   },
    //   "request": [
    //     {
    //       "cert": {
    //         "hashAlg": "sha1",
    //         "issuerNameHash": "9u2wY2IygZo19o11oJ0CShGqbK0=",
    //         "issuerKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
    //         "serialNumber": "6175535D87BF94B6"
    //       }
    //     }
    //   ]
    // }

    const ocsp_request = try chilkat.BinData.init();
    defer ocsp_request.deinit();
    const http = try chilkat.Http.init();
    defer http.deinit();

    // Convert our JSON to a binary (ASN.1) OCSP request
    http.createOcspRequest(json, ocsp_request) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    // Send the OCSP request to the OCSP server
    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpBd("POST", ocsp_url, ocsp_request, "application/ocsp-request", resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    // Get the binary (ASN.1) OCSP reply
    const ocsp_reply = try chilkat.BinData.init();
    defer ocsp_reply.deinit();
    resp.getBodyBd(ocsp_reply) catch {};

    // Convert the binary reply to JSON.
    // Also returns the overall OCSP response status.
    const json_reply = try chilkat.JsonObject.init();
    defer json_reply.deinit();
    const ocsp_status = http.parseOcspReply(ocsp_reply, json_reply);

    // The ocspStatus can have one of these values:
    // -1:  The ARG1 does not contain a valid OCSP reply.
    // 0:  Successful - Response has valid confirmations..
    // 1: Malformed request - Illegal confirmation request.
    // 2: Internal error - Internal error in issuer.
    // 3: Try later -  Try again later.
    // 4: Not used - This value is never returned.
    // 5: Sig required - Must sign the request.
    // 6: Unauthorized - Request unauthorized.

    if (ocsp_status < 0) {
        std.debug.print("Invalid OCSP reply.\n", .{});
        return;
    }

    std.debug.print("Overall OCSP Response Status: {d}\n", .{ocsp_status});

    // Let's examine the OCSP response (in JSON).
    json_reply.setEmitCompact(false);
    std.debug.print("{s}\n", .{try json_reply.emit(alloc)});

    // The JSON reply looks like this:
    // (Use the online tool at https://tools.chilkat.io/jsonParse.cshtml
    // to generate JSON parsing code.)

    // {
    //   "responseStatus": 0,
    //   "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
    //   "responseTypeName": "ocspBasic",
    //   "response": {
    //     "responderIdChoice": "KeyHash",
    //     "responderKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
    //     "dateTime": "20180803193937Z",
    //     "cert": [
    //       {
    //         "hashOid": "1.3.14.3.2.26",
    //         "hashAlg": "SHA-1",
    //         "issuerNameHash": "9u2wY2IygZo19o11oJ0CShGqbK0=",
    //         "issuerKeyHash": "d8K4UJpndnaxLcKG0IOgfqZ+uks=",
    //         "serialNumber": "6175535D87BF94B6",
    //         "status": 0,
    //         "thisUpdate": "20180803193937Z",
    //         "nextUpdate": "20180810193937Z"
    //       }
    //     ]
    //   }
    // }
    //

    // The certificate status:
    var cert_status: i32 = -1;
    if (json_reply.hasMember("response.cert[0].status")) {
        cert_status = json_reply.intOf("response.cert[0].status");
    }

    // Possible certStatus values are:
    // -1: No status returned.
    // 0: Good
    // 1: Revoked
    // 2: Unknown.
    std.debug.print("Certificate Status: {d}\n", .{cert_status});
}