<?xml version="1.0" encoding="iso-8859-1"?> <!-- $Revision: 1.2 $ --> <!-- splitted from ./en/functions/openssl.xml, last change in rev 1.4 --> <refentry id="function.openssl-pkcs7-verify"> <refnamediv> <refname>openssl_pkcs7_verify</refname> <refpurpose>Verifies the signature of an S/MIME signed message</refpurpose> </refnamediv> <refsect1> <title>Description</title> <methodsynopsis> <type>bool</type><methodname>openssl_pkcs7_verify</methodname> <methodparam><type>string</type><parameter>filename</parameter></methodparam> <methodparam><type>int</type><parameter>flags</parameter></methodparam> <methodparam choice="opt"><type>string</type><parameter>outfilename</parameter></methodparam> <methodparam choice="opt"><type>array</type><parameter>cainfo</parameter></methodparam> <methodparam choice="opt"><type>string</type><parameter>extracerts</parameter></methodparam> </methodsynopsis> &warn.experimental.func; <para> <function>openssl_pkcs7_verify</function> reads the S/MIME message contained in the filename specified by <parameter>filename</parameter> and examines the digital signature. It returns &true; if the signature is verified, &false; if it is not correct (the message has been tampered with, or the signing certificate is invalid), or -1 on error. </para> <para> <parameter>flags</parameter> can be used to affect how the signature is verified - see <link linkend="openssl.pkcs7.flags">PKCS7 constants</link> for more information. </para> <para> If the <parameter>outfilename</parameter> is specified, it should be a string holding the name of a file into which the certificates of the persons that signed the messages will be stored in PEM format. </para> <para> If the <parameter>cainfo</parameter> is specified, it should hold information about the trusted CA certificates to use in the verification process - see <link linkend="openssl.cert.verification">certificate verification</link> for more information about this parameter. </para> <para> If the <parameter>extracerts</parameter> is specified, it is the filename of a file containing a bunch of certificates to use as untrusted CAs. </para> <note> <para>This function was added in 4.0.6.</para> </note> </refsect1> </refentry> <!-- Keep this comment at the end of the file Local variables: mode: sgml sgml-omittag:t sgml-shorttag:t sgml-minimize-attributes:nil sgml-always-quote-attributes:t sgml-indent-step:1 sgml-indent-data:t indent-tabs-mode:nil sgml-parent-document:nil sgml-default-dtd-file:"../../../../manual.ced" sgml-exposed-tags:nil sgml-local-catalogs:nil sgml-local-ecat-files:nil End: vim600: syn=xml fen fdm=syntax fdl=2 si vim: et tw=78 syn=sgml vi: ts=1 sw=1 -->