Sample code for 30+ languages & platforms
Zig

Get PDF DSS (Document Security Store)

See more PDF Signatures Examples

This example demonstrates how to extract the information from a PDF's DSS (Document Security Store), if a /DSS exists. (Just because a PDF is signed does not mean a /DSS will exists. In fact, the /DSS is typically created at the point of adding the 2nd or greater signature because the /DSS contains LTV (long term validation) information about the previous signature at the time of adding an additional signature.)

Note: This example requires Chilkat v9.5.0.85 or greater.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const pdf = try chilkat.Pdf.init();
    defer pdf.deinit();

    pdf.loadFile("qa_data/pdf/sign_testing_1/helloSigned2.pdf") catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        return;
    };

    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.setEmitCompact(false);

    try pdf.getDss(json);
    std.debug.print("{s}\n", .{try json.emit(alloc)});

    // The document security store contains certificates, OCSP responses, and CRLs.
    // The following JSON is a sample of what the /DSS can contain.
    // Unfortunately, our sample contains /Certs and /OCSPs, but no /CRLs.
    // It's no problem because whatever JSON you get back, you can use the
    // following online tool to generate code to parse.
    // Generate Parsing Code from JSON

    // The code generated by the online tool for this JSON is shown below..

    // {
    //   "/VRI": {
    //     "/EC5BB34CC1F8A0C5FE674427E16E313A08C80808": {}
    //   },
    //   "/Certs": [
    //     {
    //       "serial": "02",
    //       "validFrom": "2011-08-07T19:00:00-05:00",
    //       "validTo": "2021-08-10T23:59:59-05:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "XYZ Corporation",
    //         "O": "XYZ"
    //       },
    //       "issuer": {
    //         "CN": "XYZ Corporation",
    //         "O": "XYZ"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "2048",
    //       "der": "MIIDz...Q4Zt"
    //     },
    //     {
    //       "serial": "01",
    //       "validFrom": "2011-08-07T19:00:00-05:00",
    //       "validTo": "2021-08-10T23:59:59-05:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "XYZ Corporation",
    //         "O": "XYZ"
    //       },
    //       "issuer": {
    //         "CN": "XYZ Corporation",
    //         "O": "XYZ"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "2048",
    //       "der": "MIID...jXYFc="
    //     },
    //     {
    //       "serial": "0AA125D6D6321B7E41E405DA3697C215",
    //       "validFrom": "2016-01-07T06:00:00-06:00",
    //       "validTo": "2031-01-07T12:00:00-06:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "DigiCert SHA2 Assured ID Timestamping CA",
    //         "OU": "www.digicert.com",
    //         "O": "DigiCert Inc",
    //         "C": "US"
    //       },
    //       "issuer": {
    //         "CN": "DigiCert Assured ID Root CA",
    //         "OU": "www.digicert.com",
    //         "O": "DigiCert Inc",
    //         "C": "US"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "2048",
    //       "der": "MIIF...OUg=="
    //     },
    //     {
    //       "serial": "04CD3F8568AE76C61BB0FE7160CCA76D",
    //       "validFrom": "2019-09-30T19:00:00-05:00",
    //       "validTo": "2030-10-17T00:00:00-05:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "TIMESTAMP-SHA256-2019-10-15",
    //         "O": "DigiCert, Inc.",
    //         "C": "US"
    //       },
    //       "issuer": {
    //         "CN": "DigiCert SHA2 Assured ID Timestamping CA",
    //         "OU": "www.digicert.com",
    //         "O": "DigiCert Inc",
    //         "C": "US"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "2048",
    //       "der": "MIIG...MJtPc="
    //     },
    //     {
    //       "serial": "0CE7E0E517D846FE8FE560FC1BF03039",
    //       "validFrom": "2006-11-09T18:00:00-06:00",
    //       "validTo": "2031-11-10T00:00:00-06:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "DigiCert Assured ID Root CA",
    //         "OU": "www.digicert.com",
    //         "O": "DigiCert Inc",
    //         "C": "US"
    //       },
    //       "issuer": {
    //         "CN": "DigiCert Assured ID Root CA",
    //         "OU": "www.digicert.com",
    //         "O": "DigiCert Inc",
    //         "C": "US"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "2048",
    //       "der": "MIIDt...FL6Lw8g=="
    //     },
    //     {
    //       "serial": "E4D34D01798BE686424AF7F6F0C3BF41",
    //       "validFrom": "2015-03-24T10:58:16-05:00",
    //       "validTo": "2039-12-31T23:59:59-06:00",
    //       "expired": false,
    //       "subject": {
    //         "CN": "www.xyz.com"
    //       },
    //       "issuer": {
    //         "CN": "www.xyz.com"
    //       },
    //       "keyType": "RSA",
    //       "keySize": "1024",
    //       "der": "MIIB9DCCAWG...UR10lz"
    //     }
    //   ],
    //   "/OCSPs": [
    //     {
    //       "responseStatus": 0,
    //       "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
    //       "responseTypeName": "ocspBasic",
    //       "response": {
    //         "responderIdChoice": "KeyHash",
    //         "responderKeyHash": "Reuir/SSy4IxLVGLp6chnfNtyA8=",
    //         "dateTime": "20201005173921Z",
    //         "cert": [
    //           {
    //             "hashOid": "1.3.14.3.2.26",
    //             "hashAlg": "SHA-1",
    //             "issuerNameHash": "98S+C0C1w0QzPT+uuU1uONr67FE=",
    //             "issuerKeyHash": "Reuir/SSy4IxLVGLp6chnfNtyA8=",
    //             "serialNumber": "0AA125D6D6321B7E41E405DA3697C215",
    //             "status": 0,
    //             "thisUpdate": "20201005173921Z",
    //             "nextUpdate": "20201012173921Z"
    //           }
    //         ]
    //       }
    //     },
    //     {
    //       "responseStatus": 0,
    //       "responseTypeOid": "1.3.6.1.5.5.7.48.1.1",
    //       "responseTypeName": "ocspBasic",
    //       "response": {
    //         "responderIdChoice": "KeyHash",
    //         "responderKeyHash": "9LbhIB3+Ka7S5GGlsqIlssgXNW4=",
    //         "dateTime": "20201006114501Z",
    //         "cert": [
    //           {
    //             "hashOid": "1.3.14.3.2.26",
    //             "hashAlg": "SHA-1",
    //             "issuerNameHash": "+YYA+KSr7NIxRSxCjUNQo25SyD0=",
    //             "issuerKeyHash": "9LbhIB3+Ka7S5GGlsqIlssgXNW4=",
    //             "serialNumber": "04CD3F8568AE76C61BB0FE7160CCA76D",
    //             "status": 0,
    //             "thisUpdate": "20201006114501Z",
    //             "nextUpdate": "20201013110001Z"
    //           }
    //         ]
    //       }
    //     }
    //   ]
    // }

    const response_date_time = try chilkat.DtObj.init();
    defer response_date_time.deinit();
    const this_update = try chilkat.DtObj.init();
    defer this_update.deinit();
    const next_update = try chilkat.DtObj.init();
    defer next_update.deinit();
    var serial: [:0]const u8 = "";
    var valid_from: [:0]const u8 = "";
    var valid_to: [:0]const u8 = "";
    var expired: bool = false;
    var subject_cn: [:0]const u8 = "";
    var subject_o: [:0]const u8 = "";
    var issuer_cn: [:0]const u8 = "";
    var issuer_o: [:0]const u8 = "";
    var key_type: [:0]const u8 = "";
    var key_size: [:0]const u8 = "";
    var der: [:0]const u8 = "";
    var subject_ou: [:0]const u8 = "";
    var subject_c: [:0]const u8 = "";
    var issuer_ou: [:0]const u8 = "";
    var issuer_c: [:0]const u8 = "";
    var response_status: i32 = 0;
    var response_type_oid: [:0]const u8 = "";
    var response_type_name: [:0]const u8 = "";
    var response_responder_id_choice: [:0]const u8 = "";
    var response_responder_key_hash: [:0]const u8 = "";
    var j: i32 = 0;
    var count_j: i32 = 0;
    var hash_oid: [:0]const u8 = "";
    var hash_alg: [:0]const u8 = "";
    var issuer_name_hash: [:0]const u8 = "";
    var issuer_key_hash: [:0]const u8 = "";
    var serial_number: [:0]const u8 = "";
    var status: i32 = 0;

    var i: i32 = 0;
    var count_i: i32 = json.sizeOfArray("/Certs");
    while (i < count_i) {
        json.setI(i);
        serial = try json.stringOf(alloc, "/Certs[i].serial");
        valid_from = try json.stringOf(alloc, "/Certs[i].validFrom");
        valid_to = try json.stringOf(alloc, "/Certs[i].validTo");
        expired = json.boolOf("/Certs[i].expired");
        subject_cn = try json.stringOf(alloc, "/Certs[i].subject.CN");
        subject_o = try json.stringOf(alloc, "/Certs[i].subject.O");
        issuer_cn = try json.stringOf(alloc, "/Certs[i].issuer.CN");
        issuer_o = try json.stringOf(alloc, "/Certs[i].issuer.O");
        key_type = try json.stringOf(alloc, "/Certs[i].keyType");
        key_size = try json.stringOf(alloc, "/Certs[i].keySize");
        der = try json.stringOf(alloc, "/Certs[i].der");
        subject_ou = try json.stringOf(alloc, "/Certs[i].subject.OU");
        subject_c = try json.stringOf(alloc, "/Certs[i].subject.C");
        issuer_ou = try json.stringOf(alloc, "/Certs[i].issuer.OU");
        issuer_c = try json.stringOf(alloc, "/Certs[i].issuer.C");
        i = i + 1;
    }

    i = 0;
    count_i = json.sizeOfArray("/OCSPs");
    while (i < count_i) {
        json.setI(i);
        response_status = json.intOf("/OCSPs[i].responseStatus");
        response_type_oid = try json.stringOf(alloc, "/OCSPs[i].responseTypeOid");
        response_type_name = try json.stringOf(alloc, "/OCSPs[i].responseTypeName");
        response_responder_id_choice = try json.stringOf(alloc, "/OCSPs[i].response.responderIdChoice");
        response_responder_key_hash = try json.stringOf(alloc, "/OCSPs[i].response.responderKeyHash");
        json.dtOf("/OCSPs[i].response.dateTime", false, response_date_time) catch {};
        j = 0;
        count_j = json.sizeOfArray("/OCSPs[i].response.cert");
        while (j < count_j) {
            json.setJ(j);
            hash_oid = try json.stringOf(alloc, "/OCSPs[i].response.cert[j].hashOid");
            hash_alg = try json.stringOf(alloc, "/OCSPs[i].response.cert[j].hashAlg");
            issuer_name_hash = try json.stringOf(alloc, "/OCSPs[i].response.cert[j].issuerNameHash");
            issuer_key_hash = try json.stringOf(alloc, "/OCSPs[i].response.cert[j].issuerKeyHash");
            serial_number = try json.stringOf(alloc, "/OCSPs[i].response.cert[j].serialNumber");
            status = json.intOf("/OCSPs[i].response.cert[j].status");
            json.dtOf("/OCSPs[i].response.cert[j].thisUpdate", false, this_update) catch {};
            json.dtOf("/OCSPs[i].response.cert[j].nextUpdate", false, next_update) catch {};
            j = j + 1;
        }

        i = i + 1;
    }
}