Tcl
Tcl
Create an Opaque (Attached) S/MIME Signature
See more MIME Examples
Demonstrates the Chilkat Mime.ConvertToSigned method, which creates an opaque (attached) S/MIME signature. The only argument is the signing Cert. On success the entity is replaced by a CMS/PKCS #7 signed-data structure that wraps the content inside the signature.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: An opaque signature bundles the content inside the CMS structure, so the message is a single
application/pkcs7-mime blob that only S/MIME-aware software can read. It is more tamper-resistant in transit — nothing can alter the content without breaking the wrapper — at the cost of the backward compatibility a detached signature offers. Use it when every recipient is known to support S/MIME.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set mime [new_CkMime]
set success [CkMime_SetBodyFromPlainText $mime "This message will be signed."]
if {$success == 0} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
exit
}
# Load the signing certificate (which must have access to its private key) from a PFX file.
# The PFX password should come from a secure source rather than being hard-coded.
set pfxPassword "myPfxPassword"
set cert [new_CkCert]
set success [CkCert_LoadPfxFile $cert "qa_data/signer.pfx" $pfxPassword]
if {$success == 0} then {
puts [CkCert_lastErrorText $cert]
delete_CkMime $mime
delete_CkCert $cert
exit
}
# Create an OPAQUE (attached) S/MIME signature. The entity is replaced by a CMS/PKCS #7
# signed-data structure that wraps the content inside the signature.
set success [CkMime_ConvertToSigned $mime $cert]
if {$success == 0} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
delete_CkCert $cert
exit
}
set success [CkMime_SaveMime $mime "qa_output/signed_opaque.eml"]
if {$success == 0} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
delete_CkCert $cert
exit
}
puts "Message converted to an opaque signed message."
delete_CkMime $mime
delete_CkCert $cert