Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Verify Opaque Signature and Retrieve Signing Certificates

See more Digital Signatures Examples

Demonstrates how to verify a PCKS7 opaque digital signature (signed data), extract the original file/data, and then extract the certificate(s) that were used to sign.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    // Verify a PKCS7 signed-data (opaque signature) file and extract the original content to a file.
    crypt.verifyP7M("qa_data/p7m/opaqueSig.p7", "qa_output/originalData.dat") catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // Alternatively, we can do it in memory...
    const bin_data = try chilkat.BinData.init();
    defer bin_data.deinit();
    try bin_data.loadFile("qa_data/p7m/opaqueSig.p7");
    // Your app should check for success, but we'll skip the check for brevity..

    // If verified, the signature is unwrapped and binData is replaced with the original data that was signed.
    crypt.opaqueVerifyBd(bin_data) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // For our testing, we signed some text, so we can get it from the binData..
    std.debug.print("Original Data:\n", .{});
    std.debug.print("{s}\n", .{try bin_data.getString(alloc, "utf-8")});

    // After any method call that verifies a signature, the crypt object will contain the certificate(s)
    // that were used for signing (assuming the X.509 certs were available in the signature, which is typically the case).

    // Get each signing certificate, and build the certificate chain for each.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    const cert_chain = try chilkat.CertChain.init();
    defer cert_chain.deinit();
    const num_certs = crypt.getNumSignerCerts();
    var i: i32 = 0;
    while (i < num_certs) {
        crypt.lastSignerCert(i, cert) catch {};
        std.debug.print("{s}\n", .{try cert.getSubjectDN(alloc)});

        cert.buildCertChain(cert_chain) catch {
            std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
            return;
        };

        i = i + 1;
    }
}