如何基于spatie/ssl-certificate库判断域名SSL证书类型(OV/EV)
Great question! The spatie/ssl-certificate library doesn’t have a built-in method to directly return the certificate type (OV/EV/DV), but we can figure it out by parsing the raw certificate data and checking key identifiers. Here’s how to do it with your example using apple.com:
Step 1: Get the Certificate Object
First, use your existing code to fetch the certificate:
$certificate = SslCertificate::download()->forHost('apple.com');
Step 2: Access Raw Certificate Data
The library gives you access to the full parsed certificate data via getRawCertificateData(). This includes extensions and subject fields we need:
$rawCertificateData = $certificate->getRawCertificateData();
Step 3: Check for EV Certificate
EV (Extended Validation) certificates have a specific policy OID defined by the CA/B Forum: 2.23.140.1.1. We can look for this in the certificatePolicies extension:
$isEV = false; if (isset($rawCertificateData['extensions']['certificatePolicies'])) { $policies = $rawCertificateData['extensions']['certificatePolicies']; // Check if the EV OID exists in the policy string if (str_contains($policies, '2.23.140.1.1')) { $isEV = true; } }
Step 4: Check for OV Certificate
OV (Organization Validated) certificates will have an organization name in their subject fields, and they won’t be EV certificates. We can use the library’s getSubject() method to access this:
$isOV = false; $subject = $certificate->getSubject(); // OV certs have an organizationName and are not EV if (isset($subject['organizationName']) && !$isEV) { $isOV = true; }
Quick Notes
- DV Certificates: These won’t have an
organizationNamein the subject and won’t match the EV OID. - Other EV OIDs: While
2.23.140.1.1is the standard, some older EV certs might use different OIDs. You can expand the check if needed, but this covers most modern EV certs.
Putting it all together, you can create a helper function to return the certificate type easily!
内容的提问来源于stack exchange,提问作者Nazar Yanenko

