Chilkat HOME .NET Core C# Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi ActiveX Delphi DLL Go Java Lianja Mono C# Node.js Objective-C PHP ActiveX PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift 2 Swift 3,4,5... Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(AutoIt) Verify Opaque Signature and Retrieve Signing CertificatesDemonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.
; This example assumes the Chilkat API to have been previously unlocked. ; See Global Unlock Sample for sample code. $oCrypt = ObjCreate("Chilkat_9_5_0.Crypt2") ; Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file. Local $bSuccess = $oCrypt.VerifyP7M("qa_data/p7m/opaqueSig.p7","qa_output/originalData.dat") If ($bSuccess <> True) Then ConsoleWrite($oCrypt.LastErrorText & @CRLF) Exit EndIf ; Alternatively, we can do it in memory... $oBinData = ObjCreate("Chilkat_9_5_0.BinData") $bSuccess = $oBinData.LoadFile("qa_data/p7m/opaqueSig.p7") ; Your app should check for success, but we'll skip the check for brevity.. ; If verified, the signature is unwrapped and binData is replaced with the original data that was signed. $bSuccess = $oCrypt.OpaqueVerifyBd($oBinData) If ($bSuccess <> True) Then ConsoleWrite($oCrypt.LastErrorText & @CRLF) Exit EndIf ; For our testing, we signed some text, so we can get it from the binData.. ConsoleWrite("Original Data:" & @CRLF) ConsoleWrite($oBinData.GetString("utf-8") & @CRLF) ; After any method call that verifies a signature, the crypt object will contain the certificate(s) ; that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case). ; Get the number of signing certificates, and get each.. Local $iNumCerts = $oCrypt.NumSignerCerts Local $i = 0 While $i < $iNumCerts Local $oCert = $oCrypt.GetSignerCert($i) ConsoleWrite($oCert.SubjectDN & @CRLF) $i = $i + 1 Wend ; We could also get the complete certificate chain of each signer cert, ; assuming the certs in the chain of authentication to the trusted root ; are available on the system, or provided to Chilkat by some other means ; (such as via the XmlCertVault class, the TrustedRoots class, etc.) $i = 0 While $i < $iNumCerts Local $oCertChain = $oCrypt.GetSignerCertChain($i) ; You can examine the various properties and methods for certChain in the online ; reference documentation... $i = $i + 1 Wend |
© 2000-2024 Chilkat Software, Inc. All Rights Reserved.