e0e920b1a0
Ongoing work to skip NULL check before calling free routine. This gets: ecp_nistz256_pre_comp_free nistp224_pre_comp_free nistp256_pre_comp_free nistp521_pre_comp_free PKCS7_free PKCS7_RECIP_INFO_free PKCS7_SIGNER_INFO_free sk_PKCS7_pop_free PKCS8_PRIV_KEY_INFO_free PKCS12_free PKCS12_SAFEBAG_free PKCS12_free sk_PKCS12_SAFEBAG_pop_free SSL_CONF_CTX_free SSL_CTX_free SSL_SESSION_free SSL_free ssl_cert_free ssl_sess_cert_free Reviewed-by: Kurt Roeckx <kurt@openssl.org>
76 lines
1.5 KiB
C
76 lines
1.5 KiB
C
/* Simple S/MIME verification example */
|
|
#include <openssl/pem.h>
|
|
#include <openssl/pkcs7.h>
|
|
#include <openssl/err.h>
|
|
|
|
int main(int argc, char **argv)
|
|
{
|
|
BIO *in = NULL, *out = NULL, *tbio = NULL, *cont = NULL;
|
|
X509_STORE *st = NULL;
|
|
X509 *cacert = NULL;
|
|
PKCS7 *p7 = NULL;
|
|
|
|
int ret = 1;
|
|
|
|
OpenSSL_add_all_algorithms();
|
|
ERR_load_crypto_strings();
|
|
|
|
/* Set up trusted CA certificate store */
|
|
|
|
st = X509_STORE_new();
|
|
|
|
/* Read in signer certificate and private key */
|
|
tbio = BIO_new_file("cacert.pem", "r");
|
|
|
|
if (!tbio)
|
|
goto err;
|
|
|
|
cacert = PEM_read_bio_X509(tbio, NULL, 0, NULL);
|
|
|
|
if (!cacert)
|
|
goto err;
|
|
|
|
if (!X509_STORE_add_cert(st, cacert))
|
|
goto err;
|
|
|
|
/* Open content being signed */
|
|
|
|
in = BIO_new_file("smout.txt", "r");
|
|
|
|
if (!in)
|
|
goto err;
|
|
|
|
/* Sign content */
|
|
p7 = SMIME_read_PKCS7(in, &cont);
|
|
|
|
if (!p7)
|
|
goto err;
|
|
|
|
/* File to output verified content to */
|
|
out = BIO_new_file("smver.txt", "w");
|
|
if (!out)
|
|
goto err;
|
|
|
|
if (!PKCS7_verify(p7, NULL, st, cont, out, 0)) {
|
|
fprintf(stderr, "Verification Failure\n");
|
|
goto err;
|
|
}
|
|
|
|
fprintf(stderr, "Verification Successful\n");
|
|
|
|
ret = 0;
|
|
|
|
err:
|
|
if (ret) {
|
|
fprintf(stderr, "Error Verifying Data\n");
|
|
ERR_print_errors_fp(stderr);
|
|
}
|
|
PKCS7_free(p7);
|
|
if (cacert)
|
|
X509_free(cacert);
|
|
BIO_free(in);
|
|
BIO_free(out);
|
|
BIO_free(tbio);
|
|
return ret;
|
|
}
|