Sample code for 30+ languages & platforms
Xbase++

Verify and Unwrap S/MIME, and get Information about CMS Signature

See more MIME Examples

Demonstrates calling the Verify method to verify and unwrap S/MIME. The MIME is restored to the original structure that it would have originally had prior to signing. The Verify method works with both detached signatures, as well as opaque/attached signatures.

Calls LastJsonData to get information about the signature(s) that were verified.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oMime
LOCAL nVerified
LOCAL oJson
LOCAL oSigningTime
LOCAL oAuthAttrSigningTimeUtctime
LOCAL cIssuerCN
LOCAL cSerial
LOCAL cStrVal
LOCAL cCertSerialNumber
LOCAL cCertIssuerCN
LOCAL cCertDigestAlgOid
LOCAL cCertDigestAlgName
LOCAL cContentType
LOCAL cMessageDigest
LOCAL cSigningAlgOid
LOCAL cSigningAlgName
LOCAL cAuthAttrContentTypeName
LOCAL cAuthAttrContentTypeOid
LOCAL cAuthAttrSigningTimeName
LOCAL cAuthAttrMessageDigestName
LOCAL cAuthAttrMessageDigestDigest
LOCAL cAuthAttr1_2_840_113549_1_9_15Der
LOCAL cAuthAttr1_3_6_1_4_1_311_16_4Der
LOCAL i
LOCAL nCount_i

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oMime := CreateObject("Chilkat.Mime")

//  Load the signed MIME from a file...
nSuccess := oMime:LoadMimeFile("qa_data/mime/detached_sig.eml")
IF (nSuccess == 0)
    ? oMime:LastErrorText
    oMime:destroy()
    RETURN
ENDIF

//  Verify the S/MIME and restore the MIME
//  to the structure/content it had prior to signing.
nVerified := oMime:Verify()
IF (nVerified == 0)
    ? oMime:LastErrorText
    oMime:destroy()
    RETURN
ENDIF

//  Examine the details of what was verified.
oJson := CreateObject("Chilkat.JsonObject")
oMime:GetLastJsonData(oJson)

oJson:EmitCompact := 0
? oJson:Emit()

//  The code to parse the following JSON (i.e. extract desired information) is shown below..

//  {
//    "pkcs7": {
//      "verify": {
//        "certs": [
//          {
//            "issuerCN": "VeriSign Class 1 Public Primary Certification Authority - G3",
//            "serial": "0702A21A85B84B659E180A6EE6F5A365"
//          },
//          {
//            "issuerCN": "VeriSign Class 1 Public Primary Certification Authority - G3",
//            "serial": "008B5B75568454850B00CFAF3848CEB1A4"
//          },
//          {
//            "issuerCN": "Symantec Class 1 Individual Subscriber CA - G5",
//            "serial": "619C55C32FF6BD1A7B7E0330D21C8F3C"
//          }
//        ],
//        "digestAlgorithms": [
//          "sha1"
//        ],
//        "signerInfo": [
//          {
//            "cert": {
//              "serialNumber": "619C55C32FF6BD1A7B7E0330D21C8F3C",
//              "issuerCN": "Symantec Class 1 Individual Subscriber CA - G5",
//              "digestAlgOid": "1.3.14.3.2.26",
//              "digestAlgName": "SHA1"
//            },
//            "contentType": "1.2.840.113549.1.7.1",
//            "signingTime": "160428055000Z",
//            "messageDigest": "2hJJVmO/jtaJV5uCKMFzIkRRvtY=",
//            "signingAlgOid": "1.2.840.113549.1.1.1",
//            "signingAlgName": "RSA-PKCSV-1_5",
//            "authAttr": {
//              "1.2.840.113549.1.9.3": {
//                "name": "contentType",
//                "oid": "1.2.840.113549.1.7.1"
//              },
//              "1.2.840.113549.1.9.5": {
//                "name": "signingTime",
//                "utctime": "160428055000Z"
//              },
//              "1.2.840.113549.1.9.4": {
//                "name": "messageDigest",
//                "digest": "2hJJVmO/jtaJV5uCKMFzIkRRvtY="
//              },
//              "1.2.840.113549.1.9.15": {
//                "der": "MFAwCwYJYIZIAWUDBAECMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKA=="
//              },
//              "1.3.6.1.4.1.311.16.4": {
//                "der": "MIG7MIG...7fgMw0hyPPA=="
//              }
//            }
//          }
//        ]
//      }
//    }
//  }

//  Use this online tool to generate parsing code from sample JSON: 
//  Generate Parsing Code from JSON

oSigningTime := CreateObject("Chilkat.DtObj")
oAuthAttrSigningTimeUtctime := CreateObject("Chilkat.DtObj")

i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.certs")
DO WHILE i < nCount_i
    oJson:I := i
    cIssuerCN := oJson:StringOf("pkcs7.verify.certs[i].issuerCN")
    cSerial := oJson:StringOf("pkcs7.verify.certs[i].serial")
    i := i + 1
ENDDO
i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.digestAlgorithms")
DO WHILE i < nCount_i
    oJson:I := i
    cStrVal := oJson:StringOf("pkcs7.verify.digestAlgorithms[i]")
    i := i + 1
ENDDO
i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.signerInfo")
DO WHILE i < nCount_i
    oJson:I := i
    cCertSerialNumber := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.serialNumber")
    cCertIssuerCN := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.issuerCN")
    cCertDigestAlgOid := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.digestAlgOid")
    cCertDigestAlgName := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.digestAlgName")
    cContentType := oJson:StringOf("pkcs7.verify.signerInfo[i].contentType")
    oJson:DtOf("pkcs7.verify.signerInfo[i].signingTime", 0, oSigningTime)
    cMessageDigest := oJson:StringOf("pkcs7.verify.signerInfo[i].messageDigest")
    cSigningAlgOid := oJson:StringOf("pkcs7.verify.signerInfo[i].signingAlgOid")
    cSigningAlgName := oJson:StringOf("pkcs7.verify.signerInfo[i].signingAlgName")
    cAuthAttrContentTypeName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".name')
    cAuthAttrContentTypeOid := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".oid')
    cAuthAttrSigningTimeName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".name')
    oJson:DtOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".utctime', 0, oAuthAttrSigningTimeUtctime)
    cAuthAttrMessageDigestName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".name')
    cAuthAttrMessageDigestDigest := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".digest')
    cAuthAttr1_2_840_113549_1_9_15Der := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.15".der')
    cAuthAttr1_3_6_1_4_1_311_16_4Der := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.3.6.1.4.1.311.16.4".der')
    i := i + 1
ENDDO

oMime:destroy()
oJson:destroy()
oSigningTime:destroy()
oAuthAttrSigningTimeUtctime:destroy()