Sample code for 30+ languages & platforms
AutoIt

Get PDF DSS (Document Security Store)

See more PDF Signatures Examples

This example demonstrates how to extract the information from a PDF's DSS (Document Security Store), if a /DSS exists. (Just because a PDF is signed does not mean a /DSS will exists. In fact, the /DSS is typically created at the point of adding the 2nd or greater signature because the /DSS contains LTV (long term validation) information about the previous signature at the time of adding an additional signature.)

Note: This example requires Chilkat v9.5.0.85 or greater.

Chilkat AutoIt Downloads

AutoIt
Local $bSuccess = False

; This example requires the Chilkat API to have been previously unlocked.
; See Global Unlock Sample for sample code.

$oPdf = ObjCreate("Chilkat.Pdf")

$bSuccess = $oPdf.LoadFile("qa_data/pdf/sign_testing_1/helloSigned2.pdf")
If ($bSuccess = False) Then
    ConsoleWrite($oPdf.LastErrorText & @CRLF)
    Exit
EndIf

$oJson = ObjCreate("Chilkat.JsonObject")
$oJson.EmitCompact = False

$bSuccess = $oPdf.GetDss($oJson)
ConsoleWrite($oJson.Emit() & @CRLF)

; The document security store contains certificates, OCSP responses, and CRLs.
; The following JSON is a sample of what the /DSS can contain.
; Unfortunately, our sample contains /Certs and /OCSPs, but no /CRLs.
; It's no problem because whatever JSON you get back, you can use the
; following online tool to generate code to parse.
; Generate Parsing Code from JSON

; The code generated by the online tool for this JSON is shown below..

; {
;   "/VRI": {
;     "/EC5BB34CC1F8A0C5FE674427E16E313A08C80808": {}
;   },
;   "/Certs": [
;     {
;       "serial": "02",
;       "validFrom": "2011-08-07T19:00:00-05:00",
;       "validTo": "2021-08-10T23:59:59-05:00",
;       "expired": false,
;       "subject": {
;         "CN": "XYZ Corporation",
;         "O": "XYZ"
;       },
;       "issuer": {
;         "CN": "XYZ Corporation",
;         "O": "XYZ"
;       },
;       "keyType": "RSA",
;       "keySize": "2048",
;       "der": "MIIDz...Q4Zt"
;     },
;     {
;       "serial": "01",
;       "validFrom": "2011-08-07T19:00:00-05:00",
;       "validTo": "2021-08-10T23:59:59-05:00",
;       "expired": false,
;       "subject": {
;         "CN": "XYZ Corporation",
;         "O": "XYZ"
;       },
;       "issuer": {
;         "CN": "XYZ Corporation",
;         "O": "XYZ"
;       },
;       "keyType": "RSA",
;       "keySize": "2048",
;       "der": "MIID...jXYFc="
;     },
;     {
;       "serial": "0AA125D6D6321B7E41E405DA3697C215",
;       "validFrom": "2016-01-07T06:00:00-06:00",
;       "validTo": "2031-01-07T12:00:00-06:00",
;       "expired": false,
;       "subject": {
;         "CN": "DigiCert SHA2 Assured ID Timestamping CA",
;         "OU": "www.digicert.com",
;         "O": "DigiCert Inc",
;         "C": "US"
;       },
;       "issuer": {
;         "CN": "DigiCert Assured ID Root CA",
;         "OU": "www.digicert.com",
;         "O": "DigiCert Inc",
;         "C": "US"
;       },
;       "keyType": "RSA",
;       "keySize": "2048",
;       "der": "MIIF...OUg=="
;     },
;     {
;       "serial": "04CD3F8568AE76C61BB0FE7160CCA76D",
;       "validFrom": "2019-09-30T19:00:00-05:00",
;       "validTo": "2030-10-17T00:00:00-05:00",
;       "expired": false,
;       "subject": {
;         "CN": "TIMESTAMP-SHA256-2019-10-15",
;         "O": "DigiCert, Inc.",
;         "C": "US"
;       },
;       "issuer": {
;         "CN": "DigiCert SHA2 Assured ID Timestamping CA",
;         "OU": "www.digicert.com",
;         "O": "DigiCert Inc",
;         "C": "US"
;       },
;       "keyType": "RSA",
;       "keySize": "2048",
;       "der": "MIIG...MJtPc="
;     },
;     {
;       "serial": "0CE7E0E517D846FE8FE560FC1BF03039",
;       "validFrom": "2006-11-09T18:00:00-06:00",
;       "validTo": "2031-11-10T00:00:00-06:00",
;       "expired": false,
;       "subject": {
;         "CN": "DigiCert Assured ID Root CA",
;         "OU": "www.digicert.com",
;         "O": "DigiCert Inc",
;         "C": "US"
;       },
;       "issuer": {
;         "CN": "DigiCert Assured ID Root CA",
;         "OU": "www.digicert.com",
;         "O": "DigiCert Inc",
;         "C": "US"
;       },
;       "keyType": "RSA",
;       "keySize": "2048",
;       "der": "MIIDt...FL6Lw8g=="
;     },
;     {
;       "serial": "E4D34D01798BE686424AF7F6F0C3BF41",
;       "validFrom": "2015-03-24T10:58:16-05:00",
;       "validTo": "2039-12-31T23:59:59-06:00",
;       "expired": false,
;       "subject": {
;         "CN": "www.xyz.com"
;       },
;       "issuer": {
;         "CN": "www.xyz.com"
;       },
;       "keyType": "RSA",
;       "keySize": "1024",
;       "der": "MIIB9DCCAWG...UR10lz"
;     }
;   ],
;   "/OCSPs": [
;     {
;       "responseStatus": 0,
;       "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
;       "responseTypeName": "ocspBasic",
;       "response": {
;         "responderIdChoice": "KeyHash",
;         "responderKeyHash": "Reuir/SSy4IxLVGLp6chnfNtyA8=",
;         "dateTime": "20201005173921Z",
;         "cert": [
;           {
;             "hashOid": "1.3.14.3.2.26",
;             "hashAlg": "SHA-1",
;             "issuerNameHash": "98S+C0C1w0QzPT+uuU1uONr67FE=",
;             "issuerKeyHash": "Reuir/SSy4IxLVGLp6chnfNtyA8=",
;             "serialNumber": "0AA125D6D6321B7E41E405DA3697C215",
;             "status": 0,
;             "thisUpdate": "20201005173921Z",
;             "nextUpdate": "20201012173921Z"
;           }
;         ]
;       }
;     },
;     {
;       "responseStatus": 0,
;       "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
;       "responseTypeName": "ocspBasic",
;       "response": {
;         "responderIdChoice": "KeyHash",
;         "responderKeyHash": "9LbhIB3+Ka7S5GGlsqIlssgXNW4=",
;         "dateTime": "20201006114501Z",
;         "cert": [
;           {
;             "hashOid": "1.3.14.3.2.26",
;             "hashAlg": "SHA-1",
;             "issuerNameHash": "+YYA+KSr7NIxRSxCjUNQo25SyD0=",
;             "issuerKeyHash": "9LbhIB3+Ka7S5GGlsqIlssgXNW4=",
;             "serialNumber": "04CD3F8568AE76C61BB0FE7160CCA76D",
;             "status": 0,
;             "thisUpdate": "20201006114501Z",
;             "nextUpdate": "20201013110001Z"
;           }
;         ]
;       }
;     }
;   ]
; }

$oResponseDateTime = ObjCreate("Chilkat.DtObj")
$oThisUpdate = ObjCreate("Chilkat.DtObj")
$oNextUpdate = ObjCreate("Chilkat.DtObj")
Local $serial
Local $sValidFrom
Local $sValidTo
Local $bExpired
Local $subjectCN
Local $subjectO
Local $sIssuerCN
Local $sIssuerO
Local $sKeyType
Local $sKeySize
Local $sDer
Local $subjectOU
Local $subjectC
Local $sIssuerOU
Local $sIssuerC
Local $iResponseStatus
Local $sResponseTypeOid
Local $sResponseTypeName
Local $sResponseResponderIdChoice
Local $sResponseResponderKeyHash
Local $iJ
Local $iCount_j
Local $sHashOid
Local $sHashAlg
Local $sIssuerNameHash
Local $sIssuerKeyHash
Local $serialNumber
Local $iStatus

Local $i = 0
Local $iCount_i = $oJson.SizeOfArray("/Certs")
While $i < $iCount_i
    $oJson.I = $i
    $serial = $oJson.StringOf("/Certs[i].serial")
    $sValidFrom = $oJson.StringOf("/Certs[i].validFrom")
    $sValidTo = $oJson.StringOf("/Certs[i].validTo")
    $bExpired = $oJson.BoolOf("/Certs[i].expired")
    $subjectCN = $oJson.StringOf("/Certs[i].subject.CN")
    $subjectO = $oJson.StringOf("/Certs[i].subject.O")
    $sIssuerCN = $oJson.StringOf("/Certs[i].issuer.CN")
    $sIssuerO = $oJson.StringOf("/Certs[i].issuer.O")
    $sKeyType = $oJson.StringOf("/Certs[i].keyType")
    $sKeySize = $oJson.StringOf("/Certs[i].keySize")
    $sDer = $oJson.StringOf("/Certs[i].der")
    $subjectOU = $oJson.StringOf("/Certs[i].subject.OU")
    $subjectC = $oJson.StringOf("/Certs[i].subject.C")
    $sIssuerOU = $oJson.StringOf("/Certs[i].issuer.OU")
    $sIssuerC = $oJson.StringOf("/Certs[i].issuer.C")
    $i = $i + 1
Wend
$i = 0
$iCount_i = $oJson.SizeOfArray("/OCSPs")
While $i < $iCount_i
    $oJson.I = $i
    $iResponseStatus = $oJson.IntOf("/OCSPs[i].responseStatus")
    $sResponseTypeOid = $oJson.StringOf("/OCSPs[i].responseTypeOid")
    $sResponseTypeName = $oJson.StringOf("/OCSPs[i].responseTypeName")
    $sResponseResponderIdChoice = $oJson.StringOf("/OCSPs[i].response.responderIdChoice")
    $sResponseResponderKeyHash = $oJson.StringOf("/OCSPs[i].response.responderKeyHash")
    $oJson.DtOf("/OCSPs[i].response.dateTime",False,$oResponseDateTime)
    $iJ = 0
    $iCount_j = $oJson.SizeOfArray("/OCSPs[i].response.cert")
    While $iJ < $iCount_j
        $oJson.J = $iJ
        $sHashOid = $oJson.StringOf("/OCSPs[i].response.cert[j].hashOid")
        $sHashAlg = $oJson.StringOf("/OCSPs[i].response.cert[j].hashAlg")
        $sIssuerNameHash = $oJson.StringOf("/OCSPs[i].response.cert[j].issuerNameHash")
        $sIssuerKeyHash = $oJson.StringOf("/OCSPs[i].response.cert[j].issuerKeyHash")
        $serialNumber = $oJson.StringOf("/OCSPs[i].response.cert[j].serialNumber")
        $iStatus = $oJson.IntOf("/OCSPs[i].response.cert[j].status")
        $oJson.DtOf("/OCSPs[i].response.cert[j].thisUpdate",False,$oThisUpdate)
        $oJson.DtOf("/OCSPs[i].response.cert[j].nextUpdate",False,$oNextUpdate)
        $iJ = $iJ + 1
    Wend
    $i = $i + 1
Wend