TITARD wrote:
>
> Hi everyone,
>
> I am trying to build an S/MIME client with openssl.
> the messages I received have a digital envelope (bulk + signature
> are encrypted together) and a certificate but
> no recursivity (in the sense that there no encrypted message within the
> first encrypted one). This client would replace a MIME-client in a fully
> automated management system; it needs both ends - the actual sending/recieving
> is done by Unix sendmail (HP-UX and Solaris).
>
> I have two questions:
>
> * has anybody written some script based on the command openssl (or a mix
> C-code/script-wrapper) that I could use as a starting point?
>
> * has anybody some sample code (using lib openssl) that could be of help in
> that matter?
>
> advice on the matter would be very welcomed - I mean:
> is building a S/MIME client really tough (in the sense that the routines of
> the library are really low-level) or can i manage getting a first approximation
> in say 5-10 pages of code?
>
OpenSSL 0.9.5 will have a simplified high level S/MIME API and a command
line 'smime' utility as part of the 'openssl' command line tool. This
makes it possible to write a minimal S/MIME client in 5-10 *lines* of
code.
It doesn't (yet) automatically maintain a user certificate database or
do clever stuff like working out the encryption certificate if its not
the same as the signers, or working out the supported ciphers.
I suggest you download the latest snapshot, read the 'smime' utility
docs and see what (if anything) is missing.
You can do similar stuff in 0.9.4 but you need to handle lots of yucky
low level stuff and to the MIME parsing yourself.
Steve.
--
Dr Stephen N. Henson. http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED]
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]