Objective-C
Objective-C
Verify Opaque Signature and Retrieve Signing Certificates
See more Digital Signatures Examples
Demonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.Chilkat Objective-C Downloads
#import <CkoCrypt2.h>
#import <CkoBinData.h>
#import <CkoCert.h>
#import <CkoCertChain.h>
BOOL success = NO;
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
CkoCrypt2 *crypt = [[CkoCrypt2 alloc] init];
// Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file.
success = [crypt VerifyP7M: @"qa_data/p7m/opaqueSig.p7" destPath: @"qa_output/originalData.dat"];
if (success == NO) {
NSLog(@"%@",crypt.LastErrorText);
return;
}
// Alternatively, we can do it in memory...
CkoBinData *binData = [[CkoBinData alloc] init];
success = [binData LoadFile: @"qa_data/p7m/opaqueSig.p7"];
// Your app should check for success, but we'll skip the check for brevity..
// If verified, the signature is unwrapped and binData is replaced with the original data that was signed.
success = [crypt OpaqueVerifyBd: binData];
if (success == NO) {
NSLog(@"%@",crypt.LastErrorText);
return;
}
// For our testing, we signed some text, so we can get it from the binData..
NSLog(@"%@",@"Original Data:");
NSLog(@"%@",[binData GetString: @"utf-8"]);
// After any method call that verifies a signature, the crypt object will contain the certificate(s)
// that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case).
// Get each signing certificate, and build the certificate chain for each.
CkoCert *cert = [[CkoCert alloc] init];
CkoCertChain *certChain = [[CkoCertChain alloc] init];
int numCerts = [crypt.NumSignerCerts intValue];
int i = 0;
while (i < numCerts) {
[crypt LastSignerCert: [NSNumber numberWithInt: i] cert: cert];
NSLog(@"%@",cert.SubjectDN);
success = [cert BuildCertChain: certChain];
if (success == NO) {
NSLog(@"%@",cert.LastErrorText);
return;
}
i = i + 1;
}