Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Decrypt S/MIME and Verify S/MIME Signatures

See more MIME Examples

_LANGUAGE_ example to decrypt S/MIME and verify S/MIME signatures. The S/MIME is unwrapped to get the original MIME prior to signing/encrypting.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const mime = try chilkat.Mime.init();
    defer mime.deinit();

    // Load an S/MIME message from a file:
    mime.loadMimeFile("signedMime.txt") catch {
        std.debug.print("{s}\n", .{try mime.getLastErrorText(alloc)});
        return;
    };

    // The ContainsEncryptedParts/ContainsSignedParts methods
    // can be called to determine if the MIME is encrypted and/or signed:
    const is_encrypted = mime.containsEncryptedParts();
    const is_signed = mime.containsSignedParts();

    // We don't want the "unwrap extras".  You'll see what those
    // are in a few moments...
    mime.setUnwrapExtras(false);

    // To verify the signature, call UnwrapSecurity.  This will
    // verify the signature(s) and decrypt the S/MIME and restore
    // the MIME to the unsigned/unencrypted state.
    // The results of what was found are present in the MIME object's
    // properties, as well as extra header fields that are added
    // to the unwrapped MIME.
    mime.unwrapSecurity() catch {
        // UnwrapSecurity returns true if all signatures were
        // verified and all parts decrypted.
        std.debug.print("{s}\n", .{try mime.getLastErrorText(alloc)});
        return;
    };

    // The mime.UnwrapExtras property controls whether or not
    // these additional fields are added to the unwrapped MIME:
    //
    // X-NumPartsSigned: 1
    // X-SignaturesValid: yes
    // X-NumPartsEncrypted: 1
    // X-Decrypted: no
    //
    // The X-NumPartsSigned/X-SignaturesValid headers are added
    // if the MIME was signed.
    //
    // The X-NumPartsEncrypted/X-Decrypted headers are added
    // if the MIME was encrypted.
    //

    // If the MIME was signed, get the certificate used for signing.
    if (is_signed) {
        const signer_cert = try chilkat.Cert.init();
        defer signer_cert.deinit();

        // The NumSignerCerts property indicates how many certificates
        // were used for signing.  This example will assume the value is 1.
        // To get the 1st signer cert, call LastSignerCert with an index of 0:
        if (mime.lastSignerCert(0, signer_cert)) {
            std.debug.print("**** Signer Cert: {s}\n", .{try signer_cert.getSubjectCN(alloc)});
        } else |_| {}
    }

    // If the MIME was encrypted, get the certificate used for decryption
    if (is_encrypted) {
        // The NumDecryptCerts property indicates how many certificates
        // were used for decrypting.  This example will assume the value is 1.
        // To get the 1st decrypt cert, call LastDecryptCert with an index of 0:
        const decrypt_cert = try chilkat.Cert.init();
        defer decrypt_cert.deinit();
        if (mime.lastDecryptCert(0, decrypt_cert)) {
            std.debug.print("**** Decrypt Cert: {s}\n", .{try decrypt_cert.getSubjectCN(alloc)});
        } else |_| {}
    }

    // Display the unwrapped MIME:
    std.debug.print("{s}\n", .{try mime.getMime(alloc)});

    // Save the unwrapped MIME to a file:
    try mime.saveMime("unwrappedMime.txt");
}