Tcl
Tcl
Get the S/MIME Signer's Certificate
See more MIME Examples
Demonstrates the Chilkat Mime.LastSignerCert method, which loads the signer certificate at a zero-based index from the most recent successful verification (or security-unwrapping) into a Cert. The first argument is the signer index and the second is the receiving Cert.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: Verifying tells you the signature is mathematically valid, but you usually also need to know who signed — the subject, the issuer, the validity dates — to decide whether to trust it. This retrieves each signer's certificate after verification so your code can inspect and apply its own trust rules. A message can have multiple signers, so iterate from
0 to NumSignerCerts - 1.Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set mime [new_CkMime]
set success [CkMime_LoadMimeFile $mime "qa_data/signed.eml"]
if {$success == 0} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
exit
}
# After a successful verification, load each signer's certificate to inspect it. The 1st argument
# is the zero-based signer index and the 2nd is a Cert object that receives the certificate.
set success [CkMime_Verify $mime]
if {$success != 1} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
exit
}
set n [CkMime_get_NumSignerCerts $mime]
set cert [new_CkCert]
for {set i 0} {$i <= [expr $n - 1]} {incr i} {
set success [CkMime_LastSignerCert $mime $i $cert]
if {$success == 0} then {
puts [CkMime_lastErrorText $mime]
delete_CkMime $mime
delete_CkCert $cert
exit
}
puts "Signer $i: [CkCert_subjectCN $cert] (issued by [CkCert_issuerCN $cert])"
}
delete_CkMime $mime
delete_CkCert $cert