Sample code for 30+ languages & platforms
Zig

Create an Opaque (Attached) S/MIME Signature

See more MIME Examples

Demonstrates the Chilkat Mime.ConvertToSigned method, which creates an opaque (attached) S/MIME signature. The only argument is the signing Cert. On success the entity is replaced by a CMS/PKCS #7 signed-data structure that wraps the content inside the signature.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: An opaque signature bundles the content inside the CMS structure, so the message is a single application/pkcs7-mime blob that only S/MIME-aware software can read. It is more tamper-resistant in transit — nothing can alter the content without breaking the wrapper — at the cost of the backward compatibility a detached signature offers. Use it when every recipient is known to support S/MIME.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const mime = try chilkat.Mime.init();
    defer mime.deinit();
    mime.setBodyFromPlainText("This message will be signed.") catch {
        std.debug.print("{s}\n", .{try mime.getLastErrorText(alloc)});
        return;
    };

    // Load the signing certificate (which must have access to its private key) from a PFX file.
    // The PFX password should come from a secure source rather than being hard-coded.
    const pfx_password = "myPfxPassword";
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile("qa_data/signer.pfx", pfx_password) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Create an OPAQUE (attached) S/MIME signature.  The entity is replaced by a CMS/PKCS #7
    // signed-data structure that wraps the content inside the signature.
    mime.convertToSigned(cert) catch {
        std.debug.print("{s}\n", .{try mime.getLastErrorText(alloc)});
        return;
    };

    mime.saveMime("qa_output/signed_opaque.eml") catch {
        std.debug.print("{s}\n", .{try mime.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Message converted to an opaque signed message.\n", .{});
}