C++ 验证微软数字签名

来源:互联网 发布:品牌 用户画像 大数据 编辑:程序博客网 时间:2024/05/18 22:15

代码共享如下,在Win2K sp4/WinXP sp2上调试通过。


BOOL CheckFileTrustLPCWSTR lpFileName )
{
BOOL bRet FALSE;
WINTRUST_DATA wd = { };
WINTRUST_FILE_INFO wfi = { };
WINTRUST_CATALOG_INFO wci = { };
CATALOG_INFO ci = { };

HCATADMIN hCatAdmin NULL;
if ( !CryptCATAdminAcquireContext( &hCatAdminNULL) )
{
return FALSE;
}

HANDLE hFile CreateFileWlpFileNameGENERIC_READFILE_SHARE_READ,
NULLOPEN_EXISTING0NULL );
if INVALID_HANDLE_VALUE == hFile )
{
CryptCATAdminReleaseContexthCatAdmin);
return FALSE;
}

DWORD dwCnt 100;
BYTE byHash[100];
CryptCATAdminCalcHashFromFileHandlehFile, &dwCntbyHash);
CloseHandlehFile );

LPWSTR pszMemberTag new WCHAR[dwCnt 1];
for DWORD dw 0dw dwCnt; ++dw )
{
wsprintfW( &pszMemberTag[dw 2], L"%02X"byHash[dw] );
}

HCATINFO hCatInfo CryptCATAdminEnumCatalogFromHashhCatAdmin,
byHashdwCnt0NULL );
if NULL == hCatInfo )
{
wfi.cbStruct sizeofWINTRUST_FILE_INFO );
wfi.pcwszFilePath lpFileName;
wfi.hFile NULL;
wfi.pgKnownSubject NULL;

wd.cbStruct sizeofWINTRUST_DATA );
wd.dwUnionChoice WTD_CHOICE_FILE;
wd.pFile = &wfi;
wd.dwUIChoice WTD_UI_NONE;
wd.fdwRevocationChecks WTD_REVOKE_NONE;
wd.dwStateAction WTD_STATEACTION_IGNORE;
wd.<font co
 lor="#000000">dwProvFlags WTD_SAFER_FLAG;
wd.hWVTStateData NULL;
wd.pwszURLReference NULL;
}
else
{
CryptCATCatalogInfoFromContexthCatInfo, &ci);
wci.cbStruct sizeofWINTRUST_CATALOG_INFO );
wci.pcwszCatalogFilePath ci.wszCatalogFile;
wci.pcwszMemberFilePath lpFileName;
wci.pcwszMemberTag pszMemberTag;

wd.cbStruct sizeofWINTRUST_DATA );
wd.dwUnionChoice WTD_CHOICE_CATALOG;
wd.pCatalog = &wci;
wd.dwUIChoice WTD_UI_NONE;
wd.fdwRevocationChecks WTD_STATEACTION_VERIFY;
wd.dwProvFlags 0;
wd.hWVTStateData NULL;
wd.pwszURLReference NULL;
}
GUID action WINTRUST_ACTION_GENERIC_VERIFY_V2;
HRESULT hr WinVerifyTrustNULL, &action, &wd );
bRet SUCCEEDEDhr );

if NULL != hCatInfo )
{
CryptCATAdminReleaseCatalogContexthCatAdminhCatInfo);
}
CryptCATAdminReleaseContexthCatAdmin); 
delete[] pszMemberTag;
return bRet;
}


这段代码是在一个老外的论坛上不经意搜索到的,一个貌似德国人(因为他的注释不是英文写的,德国亦仅猜测尔,西班牙、葡萄牙、法兰西、俄罗斯亦都有可能)写的Delphi代码,其中使用了WinTrust.dll中的导出函数。使用VS2005的朋友们可以包含WinTrust.h、SoftPub.h和Mscat.h,并添加导入库WinTrust.lib;使用VC6的朋友们可以参考MSDN上的函数及结构体声明,并用函数指针进行调用。

本人补充一下一些类型,方便翻译成别的语言:
typedef struct _WINTRUST_DATA 
DWORD cbStruct;
LPVOID pPolicyCallbackData;
LPVOID pSIPClientData;
DWORD dwUIChoice;
DWORD fdwRevocationChecks;
DWORD dwUnionChoice;
union {
struct WINTRUST_FILE_INFO_pFile;
struct WINTRUST_CATALOG_INFO_pCatalog;
struct WINTRUST_BLOB_INFO_pBlob;
struct WINTRUST_SGNR_INFO_pSgnr;
struct WINTRUST_CERT_INFO_pCert;
};
DWORD dwStateAction;
HANDLE hWVTStateData;
WCHAR<span color="
#000000" style="border: 0px; outline: 0px; vertical-align: baseline; background-color: transparent; margin: 0px; padding: 0px;">pwszURLReference;
DWORD dwProvFlags;
DWORD dwUIContext;
WINTRUST_DATA, *PWINTRUST_DATA;

typedef struct WINTRUST_FILE_INFO_ 
DWORD cbStruct;
LPCWSTR pcwszFilePath;
HANDLE hFile;
GUIDpgKnownSubject;
WINTRUST_FILE_INFO, *PWINTRUCT_FILE_INFO;

typedef struct WINTRUST_CATALOG_INFO_ 
DWORD cbStructDWORD dwCatalogVersion;
LPCWSTR pcwszCatalogFilePath;
LPCWSTR pcwszMemberTag;
LPCWSTR pcwszMemberFilePath;
HANDLE hMemberFile;
WINTRUST_CATALOG_INFO, *PWINTRUST_CATALOG_INFO;

typedef struct CATALOG_INFO_
DWORD cbStruct;
WCHAR wszCatalogFile[MAX_PATH];
CATALOG_INFO;

本人再补充一下用到的API声明:
LONG WINAPI WinVerifyTrust(
__in HWND hWnd,
__in GUIDpgActionID,
__in LPVOID pWVTData
);

 
0 0