IMPORT xml MAIN DEFINE doc xml.DomDocument DEFINE root xml.DomNode DEFINE node xml.DomNode DEFINE sig xml.Signature DEFINE signnode xml.DomNode DEFINE key xml.CryptoKey DEFINE list xml.DomNodeList DEFINE isVerified INTEGER DEFINE x509 xml.CryptoX509 # Create DomDocument object LET doc = xml.DomDocument.Create() # Notice that whitespaces are significant in cryptography, # therefore it is recommended to remove unnecessary ones CALL doc.setFeature("whitespace-in-element-content",FALSE) LET x509 = xml.CryptoX509.Create() TRY CALL x509.loadPEM("apns-cert.pem") CATCH DISPLAY "Unable to load certificate :",STATUS," ",sqlca.sqlerrm EXIT PROGRAM END TRY TRY # Load original document with enveloped signature into a DomDocument object CALL doc.load("naceSignature.xml") # Because the signature can be anywhere in the original document, # we must first retrieve it LET list = doc.getElementsByTagNameNS("Signature", "http://www.w3.org/2000/09/xmldsig#") IF list.getCount() != 1 THEN DISPLAY "Unable to find one Signature node" EXIT PROGRAM (-1) ELSE LET node = list.getItem(1) END IF # Create RSA key LET key = xml.CryptoKey.Create( "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256") CALL key.loadPEM("apns.pem") # Create signature object from DomNode object and set RSA key to use LET sig = xml.Signature.CreateFromNode(node) CALL sig.setKey(key) # Verify enveloped signature validity of original document LET isVerified = sig.verify(doc) # Notice that if something has been modified in the node with # attribute 'xml:id="code"' of the original XML document with the # enveloped signature, the program will display "FAILED". IF isVerified THEN DISPLAY "Signature OK" TRY CALL x509.setFeature("X509Certificate",TRUE) LET doc = x509.save() CALL doc.setFeature("format-pretty-print",TRUE) CALL doc.save("RSAX509Certificate.xml") CATCH DISPLAY "Unable to save certificate :",STATUS END TRY ELSE DISPLAY "Signature FAILED" END IF CATCH DISPLAY "Unable to verify the enveloped signature :",status END TRY END MAIN