Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Sign Manifest File to Generate a Passbook .pkpass file

See more Digital Signatures Examples

Demonstrates how to create a Passbook .pkpass archive by creating a signature of a manifest file and then zipping to a .pkpass archive.

Note: Chilkat also has the capability to do everything in-memory (no files would be involved). If this is of interest, please send email to support@chilkatsoft.com

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // ---------------------------------------------------------------------------------------------
    // Note: Chilkat also has the capability to do everything in-memory (no files would be involved).
    // See this example:  Sign Manifest File to Generate a Passbook .pkpass in Memory
    // ---------------------------------------------------------------------------------------------

    // First create the manifest.json

    const manifest = try chilkat.JsonObject.init();
    defer manifest.deinit();
    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const zip = try chilkat.Zip.init();
    defer zip.deinit();
    zip.newZip("qa_data/p7s/pass-wallet/example.pkpass") catch {};
    // Set the AppendFromDir property to prevent that relative paths from being stored in the .pkpass archive.
    zip.setAppendFromDir("qa_data/p7s/pass-wallet/");

    crypt.setHashAlgorithm("sha1");
    // Return hashes as lowercase hex.
    crypt.setEncodingMode("hexlower");

    var file_hash: [:0]const u8 = "";
    var file_path: [:0]const u8 = "";
    file_path = "qa_data/p7s/pass-wallet/icon.png";
    file_hash = try crypt.hashFileENC(alloc, file_path);
    zip.addFile("icon.png", false) catch {};
    manifest.updateString("\"icon.png\"", file_hash) catch {};

    file_path = "qa_data/p7s/pass-wallet/icon@2x.png";
    file_hash = try crypt.hashFileENC(alloc, file_path);
    zip.addFile("icon@2x.png", false) catch {};
    manifest.updateString("\"icon@2x.png\"", file_hash) catch {};

    file_path = "qa_data/p7s/pass-wallet/logo.png";
    file_hash = try crypt.hashFileENC(alloc, file_path);
    zip.addFile("logo.png", false) catch {};
    manifest.updateString("\"logo.png\"", file_hash) catch {};

    file_path = "qa_data/p7s/pass-wallet/logo@2x.png";
    file_hash = try crypt.hashFileENC(alloc, file_path);
    zip.addFile("logo@2x.png", false) catch {};
    manifest.updateString("\"logo@2x.png\"", file_hash) catch {};

    file_path = "qa_data/p7s/pass-wallet/pass.json";
    file_hash = try crypt.hashFileENC(alloc, file_path);
    zip.addFile("pass.json", false) catch {};
    manifest.updateString("\"pass.json\"", file_hash) catch {};

    const sb_json = try chilkat.StringBuilder.init();
    defer sb_json.deinit();
    manifest.emitSb(sb_json) catch {};
    const manifest_path = "qa_data/p7s/pass-wallet/manifest.json";
    sb_json.writeFile(manifest_path, "utf-8", false) catch {};
    zip.addFile("manifest.json", false) catch {};

    // Make sure we have the Apple WWDR intermediate certificate available for
    // the cert chain in the signature.
    const cert_vault = try chilkat.XmlCertVault.init();
    defer cert_vault.deinit();
    const apple_wwdr_cert = try chilkat.Cert.init();
    defer apple_wwdr_cert.deinit();
    apple_wwdr_cert.loadByCommonName("Apple Worldwide Developer Relations Certification Authority") catch {
        std.debug.print("The Apple WWDR intermediate certificate is not installed.\n", .{});
        std.debug.print("It is available at https://developer.apple.com/certificationauthority/AppleWWDRCA.cer\n", .{});
        std.debug.print("You may alternatively load the .cer like this...\n", .{});
        apple_wwdr_cert.loadFromFile("qa_data/certs/AppleWWDRCA.cer") catch {
            std.debug.print("{s}\n", .{try apple_wwdr_cert.getLastErrorText(alloc)});
            return;
        };
    };

    cert_vault.addCert(apple_wwdr_cert) catch {};
    crypt.useCertVault(cert_vault) catch {};

    // Use a digital certificate and private key from a PFX file (.pfx or .p12).
    const pfx_path = "qa_data/pfx/cert_test123.pfx";
    const pfx_password = "test123";

    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile(pfx_path, pfx_password) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Provide the signing cert (with associated private key).
    crypt.setSigningCert(cert) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // Specify the signed attributes to be included.
    // (These attributes appear to not be necessary, but we're including
    // them just in case they become necessary in the future.)
    const json_signed_attrs = try chilkat.JsonObject.init();
    defer json_signed_attrs.deinit();
    json_signed_attrs.updateInt("contentType", 1) catch {};
    json_signed_attrs.updateInt("signingTime", 1) catch {};
    crypt.setSigningAttributes(try json_signed_attrs.emit(alloc));

    // Sign the manifest JSON file to produce a file named "signature".
    const sig_path = "qa_data/p7s/pass-wallet/signature";

    // Create the "signature" file.
    crypt.createP7S(manifest_path, sig_path) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    zip.addFile("signature", false) catch {};

    // ---------------------------------------------------------------------------------------------
    // Note: Chilkat also has the capability to do everything in-memory (no files would be involved).
    // If this is of interest, please send email to support@chilkatsoft.com
    // ---------------------------------------------------------------------------------------------

    // Create the .pkipass archive (which is a .zip archive containing the required files).
    zip.writeZipAndClose() catch {
        std.debug.print("{s}\n", .{try zip.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});
}