S/MIME example
A sample S/MIME signed message showing the multipart/signed structure and PKCS7 signature attachment produced by TrustWeaver.
TrustWeaver produces a detached S/MIME message of type multipart/signed with the protocol application/pkcs7-signature. The signed document occupies the first MIME part and the PKCS7 signature is attached as smime.p7s in the second part.
The following example shows the complete S/MIME message structure for a signed XML invoice.
Mime-Version: 1.0
Date: Tue, 04 Oct 2005 13:08:05 +2
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
micalg=SHA1; boundary="8780c814ed6d409eaf69c8f0064b0444"
--8780c814ed6d409eaf69c8f0064b0444
Content-Type: text/xml; charset="utf-8"
<SAMPLE_INVOICE xmlns="http://www.company.com/Invoice/sample/V4.2.1">
...
</SAMPLE_INVOICE>
--8780c814ed6d409eaf69c8f0064b0444
Content-Transfer-Encoding: base64
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Disposition: attachment; filename="smime.p7s"
MIIL2AYJKoZIhvcNAQcCoIILyTCCC8UCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAkqZjixMObw
...
RVrdaSwmScPgJVRYxc2ZzqkduMoEvuP76vSPsZ95CvJ2iDwP2XDPN5uwj+s2dBPbBj2LiyUC8JbaTAH
--8780c814ed6d409eaf69c8f0064b0444--
MIME header handling
When signing with S/MIME, TrustWeaver places all MIME headers that do not start with Content- at the beginning of the resulting S/MIME message. Headers that start with Content- remain as part of the plaintext body. The Mime-Version: 1.0 header is always added to the output.
If the input document has no MIME headers, TrustWeaver assumes Content-Type: text/plain; charset=us-ascii.
Document format requirements
To sign a document with S/MIME, set the document format to OTHER and set InitialContentEncoding to MIME in the request. The input document must include at least a Content-Type MIME header.
InitialContentEncoding is set to MIME. For more details, go to Document and signature format combinations.
