Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Verify a CAdES-BES Signature and Examine Signature Contents

See more Digital Signatures Examples

Demonstrates how to validate a .p7m (.p7s) signature and examine the contents of the signature.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL cOutputFile
LOCAL cInFile
LOCAL oJson
LOCAL oAuthAttrSigningTimeUtctime
LOCAL cIssuerCN
LOCAL cSerial
LOCAL cStrVal
LOCAL cCertSubjectKeyIdentifier
LOCAL cCertDigestAlgOid
LOCAL cCertDigestAlgName
LOCAL cSigningAlgOid
LOCAL cSigningAlgName
LOCAL cAuthAttrContentTypeName
LOCAL cAuthAttrContentTypeOid
LOCAL cAuthAttrSigningTimeName
LOCAL cAuthAttrMessageDigestName
LOCAL cAuthAttrMessageDigestDigest
LOCAL cAuthAttrSigningCertificateV2Name
LOCAL cAuthAttrSigningCertificateV2Der
LOCAL i
LOCAL nCount_i

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oCrypt := CreateObject("Chilkat.Crypt2")

cOutputFile := "qa_output/original.xml"
cInFile := "qa_data/p7m/fattura_signature.xml.p7m"

//  Verify the signature and extract the contained file, which in this case is XML.
nSuccess := oCrypt:VerifyP7M(cInFile, cOutputFile)
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    RETURN
ENDIF

? "Signature validated."

//  Now let's examine the information about the signature.
oJson := CreateObject("Chilkat.JsonObject")
oCrypt:GetLastJsonData(oJson)

oJson:EmitCompact := 0
? oJson:Emit()

//  Here's an example of the information about the signature:
//  {
//    "pkcs7": {
//      "verify": {
//        "certs": [
//          {
//            "issuerCN": "Xyz EU Qualified Certificates CA G1",
//            "serial": "99A28A51AC389999"
//          }
//        ],
//        "useConstructedOctets": true,
//        "digestAlgorithms": [
//          "sha256"
//        ],
//        "signerInfo": [
//          {
//            "cert": {
//              "subjectKeyIdentifier": "5VM4x8AWnXf07yzbXuLtbb0U3yY=",
//              "digestAlgOid": "2.16.840.1.101.3.4.2.1",
//              "digestAlgName": "SHA256"
//            },
//            "signingAlgOid": "1.2.840.113549.1.1.11",
//            "signingAlgName": "RSA-SHA256-PKCSV-1_5",
//            "authAttr": {
//              "1.2.840.113549.1.9.3": {
//                "name": "contentType",
//                "oid": "1.2.840.113549.1.7.1"
//              },
//              "1.2.840.113549.1.9.5": {
//                "name": "signingTime",
//                "utctime": "190901152340Z"
//              },
//              "1.2.840.113549.1.9.4": {
//                "name": "messageDigest",
//                "digest": "y+gd/zAQK33A//HInhaZba7w1fUJleV9AHbP1Ntx6U0="
//              },
//              "1.2.840.113549.1.9.16.2.47": {
//                "name": "signingCertificateV2",
//                "der": "MIH4MI..w4vv0="
//              }
//            }
//          }
//        ]
//      }
//    }
//  }

//  Use this online tool to generate parsing code from sample JSON: 
//  Generate Parsing Code from JSON

oAuthAttrSigningTimeUtctime := CreateObject("Chilkat.DtObj")

i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.certs")
DO WHILE i < nCount_i
    oJson:I := i
    cIssuerCN := oJson:StringOf("pkcs7.verify.certs[i].issuerCN")
    cSerial := oJson:StringOf("pkcs7.verify.certs[i].serial")
    i := i + 1
ENDDO
i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.digestAlgorithms")
DO WHILE i < nCount_i
    oJson:I := i
    cStrVal := oJson:StringOf("pkcs7.verify.digestAlgorithms[i]")
    i := i + 1
ENDDO
i := 0
nCount_i := oJson:SizeOfArray("pkcs7.verify.signerInfo")
DO WHILE i < nCount_i
    oJson:I := i
    cCertSubjectKeyIdentifier := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.subjectKeyIdentifier")
    cCertDigestAlgOid := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.digestAlgOid")
    cCertDigestAlgName := oJson:StringOf("pkcs7.verify.signerInfo[i].cert.digestAlgName")
    cSigningAlgOid := oJson:StringOf("pkcs7.verify.signerInfo[i].signingAlgOid")
    cSigningAlgName := oJson:StringOf("pkcs7.verify.signerInfo[i].signingAlgName")
    cAuthAttrContentTypeName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".name')
    cAuthAttrContentTypeOid := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".oid')
    cAuthAttrSigningTimeName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".name')
    oJson:DtOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".utctime', 0, oAuthAttrSigningTimeUtctime)
    cAuthAttrMessageDigestName := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".name')
    cAuthAttrMessageDigestDigest := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".digest')
    cAuthAttrSigningCertificateV2Name := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.16.2.47".name')
    cAuthAttrSigningCertificateV2Der := oJson:StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.16.2.47".der')
    i := i + 1
ENDDO

oCrypt:destroy()
oJson:destroy()
oAuthAttrSigningTimeUtctime:destroy()