Sample code for 30+ languages & platforms
AutoIt

Verify Opaque Signature and Retrieve Signing Certificates

See more Digital Signatures Examples

Demonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.

Chilkat AutoIt Downloads

AutoIt
Local $bSuccess = False

; This example assumes the Chilkat API to have been previously unlocked.
; See Global Unlock Sample for sample code.

$oCrypt = ObjCreate("Chilkat.Crypt2")

; Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file.
$bSuccess = $oCrypt.VerifyP7M("qa_data/p7m/opaqueSig.p7","qa_output/originalData.dat")
If ($bSuccess = False) Then
    ConsoleWrite($oCrypt.LastErrorText & @CRLF)
    Exit
EndIf

; Alternatively, we can do it in memory...
$oBinData = ObjCreate("Chilkat.BinData")
$bSuccess = $oBinData.LoadFile("qa_data/p7m/opaqueSig.p7")
; Your app should check for success, but we'll skip the check for brevity..

; If verified, the signature is unwrapped and binData is replaced with the original data that was signed.
$bSuccess = $oCrypt.OpaqueVerifyBd($oBinData)
If ($bSuccess = False) Then
    ConsoleWrite($oCrypt.LastErrorText & @CRLF)
    Exit
EndIf

; For our testing, we signed some text, so we can get it from the binData..
ConsoleWrite("Original Data:" & @CRLF)
ConsoleWrite($oBinData.GetString("utf-8") & @CRLF)

; After any method call that verifies a signature, the crypt object will contain the certificate(s)
; that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case).

; Get each signing certificate, and build the certificate chain for each.
$oCert = ObjCreate("Chilkat.Cert")
$oCertChain = ObjCreate("Chilkat.CertChain")
Local $iNumCerts = $oCrypt.NumSignerCerts
Local $i = 0
While $i < $iNumCerts
    $oCrypt.LastSignerCert($i,$oCert)
    ConsoleWrite($oCert.SubjectDN & @CRLF)

    $bSuccess = $oCert.BuildCertChain($oCertChain)
    If ($bSuccess = False) Then
        ConsoleWrite($oCert.LastErrorText & @CRLF)
        Exit
    EndIf

    $i = $i + 1
Wend