Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Verify a CAdES-BES Signature and Examine Signature Contents

See more Digital Signatures Examples

Demonstrates how to validate a .p7m (.p7s) signature and examine the contents of the signature.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const output_file = "qa_output/original.xml";
    const in_file = "qa_data/p7m/fattura_signature.xml.p7m";

    // Verify the signature and extract the contained file, which in this case is XML.
    crypt.verifyP7M(in_file, output_file) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Signature validated.\n", .{});

    // Now let's examine the information about the signature.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    crypt.getLastJsonData(json);

    json.setEmitCompact(false);
    std.debug.print("{s}\n", .{try json.emit(alloc)});

    // Here's an example of the information about the signature:
    // {
    //   "pkcs7": {
    //     "verify": {
    //       "certs": [
    //         {
    //           "issuerCN": "Xyz EU Qualified Certificates CA G1",
    //           "serial": "99A28A51AC389999"
    //         }
    //       ],
    //       "useConstructedOctets": true,
    //       "digestAlgorithms": [
    //         "sha256"
    //       ],
    //       "signerInfo": [
    //         {
    //           "cert": {
    //             "subjectKeyIdentifier": "5VM4x8AWnXf07yzbXuLtbb0U3yY=",
    //             "digestAlgOid": "2.16.840.1.101.3.4.2.1",
    //             "digestAlgName": "SHA256"
    //           },
    //           "signingAlgOid": "1.2.840.113549.1.1.11",
    //           "signingAlgName": "RSA-SHA256-PKCSV-1_5",
    //           "authAttr": {
    //             "1.2.840.113549.1.9.3": {
    //               "name": "contentType",
    //               "oid": "1.2.840.113549.1.7.1"
    //             },
    //             "1.2.840.113549.1.9.5": {
    //               "name": "signingTime",
    //               "utctime": "190901152340Z"
    //             },
    //             "1.2.840.113549.1.9.4": {
    //               "name": "messageDigest",
    //               "digest": "y+gd/zAQK33A//HInhaZba7w1fUJleV9AHbP1Ntx6U0="
    //             },
    //             "1.2.840.113549.1.9.16.2.47": {
    //               "name": "signingCertificateV2",
    //               "der": "MIH4MI..w4vv0="
    //             }
    //           }
    //         }
    //       ]
    //     }
    //   }
    // }

    // Use this online tool to generate parsing code from sample JSON:
    // Generate Parsing Code from JSON

    const auth_attr_signing_time_utctime = try chilkat.DtObj.init();
    defer auth_attr_signing_time_utctime.deinit();
    var issuer_cn: [:0]const u8 = "";
    var serial: [:0]const u8 = "";
    var str_val: [:0]const u8 = "";
    var cert_subject_key_identifier: [:0]const u8 = "";
    var cert_digest_alg_oid: [:0]const u8 = "";
    var cert_digest_alg_name: [:0]const u8 = "";
    var signing_alg_oid: [:0]const u8 = "";
    var signing_alg_name: [:0]const u8 = "";
    var auth_attr_content_type_name: [:0]const u8 = "";
    var auth_attr_content_type_oid: [:0]const u8 = "";
    var auth_attr_signing_time_name: [:0]const u8 = "";
    var auth_attr_message_digest_name: [:0]const u8 = "";
    var auth_attr_message_digest_digest: [:0]const u8 = "";
    var auth_attr_signing_certificate_v2_name: [:0]const u8 = "";
    var auth_attr_signing_certificate_v2_der: [:0]const u8 = "";

    var i: i32 = 0;
    var count_i: i32 = json.sizeOfArray("pkcs7.verify.certs");
    while (i < count_i) {
        json.setI(i);
        issuer_cn = try json.stringOf(alloc, "pkcs7.verify.certs[i].issuerCN");
        serial = try json.stringOf(alloc, "pkcs7.verify.certs[i].serial");
        i = i + 1;
    }

    i = 0;
    count_i = json.sizeOfArray("pkcs7.verify.digestAlgorithms");
    while (i < count_i) {
        json.setI(i);
        str_val = try json.stringOf(alloc, "pkcs7.verify.digestAlgorithms[i]");
        i = i + 1;
    }

    i = 0;
    count_i = json.sizeOfArray("pkcs7.verify.signerInfo");
    while (i < count_i) {
        json.setI(i);
        cert_subject_key_identifier = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].cert.subjectKeyIdentifier");
        cert_digest_alg_oid = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].cert.digestAlgOid");
        cert_digest_alg_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].cert.digestAlgName");
        signing_alg_oid = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].signingAlgOid");
        signing_alg_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].signingAlgName");
        auth_attr_content_type_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.3\".name");
        auth_attr_content_type_oid = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.3\".oid");
        auth_attr_signing_time_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.5\".name");
        json.dtOf("pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.5\".utctime", false, auth_attr_signing_time_utctime) catch {};
        auth_attr_message_digest_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.4\".name");
        auth_attr_message_digest_digest = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.4\".digest");
        auth_attr_signing_certificate_v2_name = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.16.2.47\".name");
        auth_attr_signing_certificate_v2_der = try json.stringOf(alloc, "pkcs7.verify.signerInfo[i].authAttr.\"1.2.840.113549.1.9.16.2.47\".der");
        i = i + 1;
    }
}