Sample code for 30+ languages & platforms
DataFlex

Verify an S/MIME Signed Message

See more MIME Examples

Demonstrates the Chilkat Mime.Verify method, which verifies a CMS/PKCS #7 signed MIME entity and removes the signature wrapper. It takes no arguments and supports both detached (multipart/signed) and opaque (signed-data) messages.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: Verification confirms two things: that the content was signed by the holder of the signer's certificate, and that it has not been altered since. On success Chilkat strips the signature layer so the object holds the original content, ready to read — effectively "open and check" in one step. A false return means the signature is invalid or the content was tampered with, which is exactly the case your code must not treat as trusted.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoMime
    String sBody
    String sTemp1
    Integer iTemp1
    Boolean bTemp1

    Move False To iSuccess

    Get Create (RefClass(cComChilkatMime)) To hoMime
    If (Not(IsComObjectCreated(hoMime))) Begin
        Send CreateComObject of hoMime
    End
    Get ComLoadMimeFile Of hoMime "qa_data/signed.eml" To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoMime To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  Verify the signature and remove the signature wrapper, restoring the underlying content.  Both
    //  detached (multipart/signed) and opaque (CMS signed-data) messages are supported.
    Get ComVerify Of hoMime To iSuccess
    If (iSuccess <> True) Begin
        Showln "Signature verification failed."
        Get ComLastErrorText Of hoMime To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Get ComNumSignerCerts Of hoMime To iTemp1
    Showln "Signature verified. Number of signers: " iTemp1

    //  The object now holds the original content with the signature removed.
    Get ComGetBodyDecoded Of hoMime To sBody
    Get ComLastMethodSuccess Of hoMime To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoMime To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln sBody


End_Procedure