Skip to content

SSL_get_verify_result

NAME

SSL_get_verify_result - get result of peer certificate verification

SYNOPSIS

#include <openssl/ssl.h>

long SSL_get_verify_result(const SSL *ssl);

DESCRIPTION

SSL_get_verify_result() returns the result of the verification of the X509 certificate or raw public key presented by the peer, if any. ssl MUST NOT be NULL.

NOTES

SSL_get_verify_result() can only return one error code while the verification of a certificate can fail because of many reasons at the same time. Only the last verification error that occurred during the processing is available from SSL_get_verify_result().

Sometimes there can be a sequence of errors leading to the verification failure as reported by SSL_get_verify_result(). To get the errors, it is necessary to setup a verify callback via SSL_CTX_set_verify(3) or SSL_set_verify(3) and retrieve the errors from the error stack there, because once SSL_connect(3) returns, these errors may no longer be available.

The verification result is part of the established session and is restored when a session is reused.

When a server accepts an empty client Certificate message during the initial handshake, the result is X509_V_OK. This applies to both X.509 certificates and raw public keys. No credential verification was performed, and this result does not establish that the peer was authenticated. The handshake can still complete if client authentication is optional.

An empty response to an optional post-handshake authentication request leaves the previous peer identity and verification result unchanged. No certificate or raw public key verification is performed for an empty response.

BUGS

In other cases where no peer certificate or raw public key was presented, the returned result can still be X509_V_OK, for example when a server did not request a client certificate during the initial handshake. X509_V_OK alone does not establish how or whether the peer was authenticated. A suitably provisioned external PSK can authenticate a peer without a certificate or raw public key. When certificate or raw public key authentication is expected, applications must also check that the expected credential is present using SSL_get_peer_certificate(3) or SSL_get0_peer_rpk(3).

RETURN VALUES

The following return values can currently occur:

  • X509_V_OK

    No verification error was recorded. A peer certificate or raw public key might not have been presented; see "BUGS".

  • Any other value

    Documented in openssl-verify(1).

SEE ALSO

ssl(7), SSL_set_verify_result(3), SSL_get_peer_certificate(3), SSL_get0_peer_rpk(3), openssl-verify(1)

Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.