1/* Simple S/MIME signing example */
2#include <openssl/pem.h>
3#include <openssl/cms.h>
4#include <openssl/err.h>
5
6int main(int argc, char **argv)
7{
8    BIO *in = NULL, *out = NULL, *tbio = NULL;
9    X509 *scert = NULL;
10    EVP_PKEY *skey = NULL;
11    CMS_ContentInfo *cms = NULL;
12    int ret = 1;
13
14    /*
15     * For simple S/MIME signing use CMS_DETACHED. On OpenSSL 1.0.0 only: for
16     * streaming detached set CMS_DETACHED|CMS_STREAM for streaming
17     * non-detached set CMS_STREAM
18     */
19    int flags = CMS_DETACHED | CMS_STREAM;
20
21    OpenSSL_add_all_algorithms();
22    ERR_load_crypto_strings();
23
24    /* Read in signer certificate and private key */
25    tbio = BIO_new_file("signer.pem", "r");
26
27    if (!tbio)
28        goto err;
29
30    scert = PEM_read_bio_X509(tbio, NULL, 0, NULL);
31
32    BIO_reset(tbio);
33
34    skey = PEM_read_bio_PrivateKey(tbio, NULL, 0, NULL);
35
36    if (!scert || !skey)
37        goto err;
38
39    /* Open content being signed */
40
41    in = BIO_new_file("sign.txt", "r");
42
43    if (!in)
44        goto err;
45
46    /* Sign content */
47    cms = CMS_sign(scert, skey, NULL, in, flags);
48
49    if (!cms)
50        goto err;
51
52    out = BIO_new_file("smout.txt", "w");
53    if (!out)
54        goto err;
55
56    if (!(flags & CMS_STREAM))
57        BIO_reset(in);
58
59    /* Write out S/MIME message */
60    if (!SMIME_write_CMS(out, cms, in, flags))
61        goto err;
62
63    ret = 0;
64
65 err:
66
67    if (ret) {
68        fprintf(stderr, "Error Signing Data\n");
69        ERR_print_errors_fp(stderr);
70    }
71
72    if (cms)
73        CMS_ContentInfo_free(cms);
74    if (scert)
75        X509_free(scert);
76    if (skey)
77        EVP_PKEY_free(skey);
78
79    if (in)
80        BIO_free(in);
81    if (out)
82        BIO_free(out);
83    if (tbio)
84        BIO_free(tbio);
85
86    return ret;
87
88}
89