Sample code for 30+ languages & platforms
Tcl

Get the S/MIME Signer's Certificate

See more MIME Examples

Demonstrates the Chilkat Mime.LastSignerCert method, which loads the signer certificate at a zero-based index from the most recent successful verification (or security-unwrapping) into a Cert. The first argument is the signer index and the second is the receiving Cert.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: Verifying tells you the signature is mathematically valid, but you usually also need to know who signed — the subject, the issuer, the validity dates — to decide whether to trust it. This retrieves each signer's certificate after verification so your code can inspect and apply its own trust rules. A message can have multiple signers, so iterate from 0 to NumSignerCerts - 1.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set mime [new_CkMime]

set success [CkMime_LoadMimeFile $mime "qa_data/signed.eml"]
if {$success == 0} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    exit
}

#  After a successful verification, load each signer's certificate to inspect it.  The 1st argument
#  is the zero-based signer index and the 2nd is a Cert object that receives the certificate.
set success [CkMime_Verify $mime]
if {$success != 1} then {
    puts [CkMime_lastErrorText $mime]
    delete_CkMime $mime
    exit
}

set n [CkMime_get_NumSignerCerts $mime]
set cert [new_CkCert]

for {set i 0} {$i <= [expr $n - 1]} {incr i} {
    set success [CkMime_LastSignerCert $mime $i $cert]
    if {$success == 0} then {
        puts [CkMime_lastErrorText $mime]
        delete_CkMime $mime
        delete_CkCert $cert
        exit
    }

    puts "Signer $i: [CkCert_subjectCN $cert] (issued by [CkCert_issuerCN $cert])"
}

delete_CkMime $mime
delete_CkCert $cert