Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Sign Manifest File to Generate a Passbook .pkpass file

See more Digital Signatures Examples

Demonstrates how to create a Passbook .pkpass archive by creating a signature of a manifest file and then zipping to a .pkpass archive.

Note: Chilkat also has the capability to do everything in-memory (no files would be involved). If this is of interest, please send email to support@chilkatsoft.com

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oManifest
LOCAL oCrypt
LOCAL oZip
LOCAL cFileHash
LOCAL cFilePath
LOCAL oSbJson
LOCAL cManifestPath
LOCAL oCertVault
LOCAL oAppleWwdrCert
LOCAL cPfxPath
LOCAL cPfxPassword
LOCAL oCert
LOCAL oJsonSignedAttrs
LOCAL cSigPath

nSuccess := 0

//  This requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  ---------------------------------------------------------------------------------------------
//  Note: Chilkat also has the capability to do everything in-memory (no files would be involved).  
//  See this example:  Sign Manifest File to Generate a Passbook .pkpass in Memory
//  ---------------------------------------------------------------------------------------------

//  First create the manifest.json

oManifest := CreateObject("Chilkat.JsonObject")
oCrypt := CreateObject("Chilkat.Crypt2")

oZip := CreateObject("Chilkat.Zip")
oZip:NewZip("qa_data/p7s/pass-wallet/example.pkpass")
//  Set the AppendFromDir property to prevent that relative paths from being stored in the .pkpass archive.
oZip:AppendFromDir := "qa_data/p7s/pass-wallet/"

oCrypt:HashAlgorithm := "sha1"
//  Return hashes as lowercase hex.
oCrypt:EncodingMode := "hexlower"

cFilePath := "qa_data/p7s/pass-wallet/icon.png"
cFileHash := oCrypt:HashFileENC(cFilePath)
oZip:AddFile("icon.png", 0)
oManifest:UpdateString('"icon.png"', cFileHash)

cFilePath := "qa_data/p7s/pass-wallet/icon@2x.png"
cFileHash := oCrypt:HashFileENC(cFilePath)
oZip:AddFile("icon@2x.png", 0)
oManifest:UpdateString('"icon@2x.png"', cFileHash)

cFilePath := "qa_data/p7s/pass-wallet/logo.png"
cFileHash := oCrypt:HashFileENC(cFilePath)
oZip:AddFile("logo.png", 0)
oManifest:UpdateString('"logo.png"', cFileHash)

cFilePath := "qa_data/p7s/pass-wallet/logo@2x.png"
cFileHash := oCrypt:HashFileENC(cFilePath)
oZip:AddFile("logo@2x.png", 0)
oManifest:UpdateString('"logo@2x.png"', cFileHash)

cFilePath := "qa_data/p7s/pass-wallet/pass.json"
cFileHash := oCrypt:HashFileENC(cFilePath)
oZip:AddFile("pass.json", 0)
oManifest:UpdateString('"pass.json"', cFileHash)

oSbJson := CreateObject("Chilkat.StringBuilder")
oManifest:EmitSb(oSbJson)
cManifestPath := "qa_data/p7s/pass-wallet/manifest.json"
oSbJson:WriteFile(cManifestPath, "utf-8", 0)
oZip:AddFile("manifest.json", 0)

//  Make sure we have the Apple WWDR intermediate certificate available for 
//  the cert chain in the signature.
oCertVault := CreateObject("Chilkat.XmlCertVault")
oAppleWwdrCert := CreateObject("Chilkat.Cert")
nSuccess := oAppleWwdrCert:LoadByCommonName("Apple Worldwide Developer Relations Certification Authority")
IF (nSuccess != 1)
    ? "The Apple WWDR intermediate certificate is not installed."
    ? "It is available at https://developer.apple.com/certificationauthority/AppleWWDRCA.cer"
    ? "You may alternatively load the .cer like this..."
    nSuccess := oAppleWwdrCert:LoadFromFile("qa_data/certs/AppleWWDRCA.cer")
    IF (nSuccess == 0)
        ? oAppleWwdrCert:LastErrorText
        oManifest:destroy()
        oCrypt:destroy()
        oZip:destroy()
        oSbJson:destroy()
        oCertVault:destroy()
        oAppleWwdrCert:destroy()
        RETURN
    ENDIF

ENDIF

oCertVault:AddCert(oAppleWwdrCert)
oCrypt:UseCertVault(oCertVault)

//  Use a digital certificate and private key from a PFX file (.pfx or .p12).
cPfxPath := "qa_data/pfx/cert_test123.pfx"
cPfxPassword := "test123"

oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadPfxFile(cPfxPath, cPfxPassword)
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oManifest:destroy()
    oCrypt:destroy()
    oZip:destroy()
    oSbJson:destroy()
    oCertVault:destroy()
    oAppleWwdrCert:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Provide the signing cert (with associated private key).
nSuccess := oCrypt:SetSigningCert(oCert)
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oManifest:destroy()
    oCrypt:destroy()
    oZip:destroy()
    oSbJson:destroy()
    oCertVault:destroy()
    oAppleWwdrCert:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Specify the signed attributes to be included.
//  (These attributes appear to not be necessary, but we're including
//  them just in case they become necessary in the future.)
oJsonSignedAttrs := CreateObject("Chilkat.JsonObject")
oJsonSignedAttrs:UpdateInt("contentType", 1)
oJsonSignedAttrs:UpdateInt("signingTime", 1)
oCrypt:SigningAttributes := oJsonSignedAttrs:Emit()

//  Sign the manifest JSON file to produce a file named "signature".
cSigPath := "qa_data/p7s/pass-wallet/signature"

//  Create the "signature" file.
nSuccess := oCrypt:CreateP7S(cManifestPath, cSigPath)
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oManifest:destroy()
    oCrypt:destroy()
    oZip:destroy()
    oSbJson:destroy()
    oCertVault:destroy()
    oAppleWwdrCert:destroy()
    oCert:destroy()
    oJsonSignedAttrs:destroy()
    RETURN
ENDIF

oZip:AddFile("signature", 0)

//  ---------------------------------------------------------------------------------------------
//  Note: Chilkat also has the capability to do everything in-memory (no files would be involved).  
//  If this is of interest, please send email to support@chilkatsoft.com
//  ---------------------------------------------------------------------------------------------

//  Create the .pkipass archive (which is a .zip archive containing the required files).
nSuccess := oZip:WriteZipAndClose()
IF (nSuccess == 0)
    ? oZip:LastErrorText
    oManifest:destroy()
    oCrypt:destroy()
    oZip:destroy()
    oSbJson:destroy()
    oCertVault:destroy()
    oAppleWwdrCert:destroy()
    oCert:destroy()
    oJsonSignedAttrs:destroy()
    RETURN
ENDIF

? "Success."

oManifest:destroy()
oCrypt:destroy()
oZip:destroy()
oSbJson:destroy()
oCertVault:destroy()
oAppleWwdrCert:destroy()
oCert:destroy()
oJsonSignedAttrs:destroy()