Sample code for 30+ languages & platforms
PowerShell Requires Chilkat v11.0.0+

Verify Opaque Signature and Retrieve Signing Certificates

See more Digital Signatures Examples

Demonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.

Chilkat PowerShell Downloads

PowerShell
Add-Type -Path "C:\chilkat\ChilkatDotNet47-x64\ChilkatDotNet47.dll"

$success = $false

#  This example assumes the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

$crypt = New-Object Chilkat.Crypt2

#  Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file.
$success = $crypt.VerifyP7M("qa_data/p7m/opaqueSig.p7","qa_output/originalData.dat")
if ($success -eq $false) {
    $($crypt.LastErrorText)
    exit
}

#  Alternatively, we can do it in memory...
$binData = New-Object Chilkat.BinData
$success = $binData.LoadFile("qa_data/p7m/opaqueSig.p7")
#  Your app should check for success, but we'll skip the check for brevity..

#  If verified, the signature is unwrapped and binData is replaced with the original data that was signed.
$success = $crypt.OpaqueVerifyBd($binData)
if ($success -eq $false) {
    $($crypt.LastErrorText)
    exit
}

#  For our testing, we signed some text, so we can get it from the binData..
$("Original Data:")
$($binData.GetString("utf-8"))

#  After any method call that verifies a signature, the crypt object will contain the certificate(s)
#  that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case).

#  Get each signing certificate, and build the certificate chain for each.
$cert = New-Object Chilkat.Cert
$certChain = New-Object Chilkat.CertChain
$numCerts = $crypt.NumSignerCerts
$i = 0
while ($i -lt $numCerts) {
    $crypt.LastSignerCert($i,$cert)
    $($cert.SubjectDN)

    $success = $cert.BuildCertChain($certChain)
    if ($success -eq $false) {
        $($cert.LastErrorText)
        exit
    }

    $i = $i + 1
}