Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Verify Opaque Signature and Retrieve Signing Certificates

See more Digital Signatures Examples

Demonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL oBinData
LOCAL oCert
LOCAL oCertChain
LOCAL nNumCerts
LOCAL i

nSuccess := 0

//  This example assumes the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oCrypt := CreateObject("Chilkat.Crypt2")

//  Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file.
nSuccess := oCrypt:VerifyP7M("qa_data/p7m/opaqueSig.p7", "qa_output/originalData.dat")
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    RETURN
ENDIF

//  Alternatively, we can do it in memory...
oBinData := CreateObject("Chilkat.BinData")
nSuccess := oBinData:LoadFile("qa_data/p7m/opaqueSig.p7")
//  Your app should check for success, but we'll skip the check for brevity..

//  If verified, the signature is unwrapped and binData is replaced with the original data that was signed.
nSuccess := oCrypt:OpaqueVerifyBd(oBinData)
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    oBinData:destroy()
    RETURN
ENDIF

//  For our testing, we signed some text, so we can get it from the binData..
? "Original Data:"
? oBinData:GetString("utf-8")

//  After any method call that verifies a signature, the crypt object will contain the certificate(s)
//  that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case).

//  Get each signing certificate, and build the certificate chain for each.
oCert := CreateObject("Chilkat.Cert")
oCertChain := CreateObject("Chilkat.CertChain")
nNumCerts := oCrypt:NumSignerCerts
i := 0
DO WHILE i < nNumCerts
    oCrypt:LastSignerCert(i, oCert)
    ? oCert:SubjectDN

    nSuccess := oCert:BuildCertChain(oCertChain)
    IF (nSuccess == 0)
        ? oCert:LastErrorText
        oCrypt:destroy()
        oBinData:destroy()
        oCert:destroy()
        oCertChain:destroy()
        RETURN
    ENDIF

    i := i + 1
ENDDO

oCrypt:destroy()
oBinData:destroy()
oCert:destroy()
oCertChain:destroy()