C
C
CMS Sign Hash
Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).This example requires Chilkat v9.5.0.90 or later.
Chilkat C Downloads
#include <C_CkCrypt2.h>
#include <C_CkCert.h>
void ChilkatSample(void)
{
BOOL success;
HCkCrypt2 crypt;
const char *base64Hash;
HCkCert cert;
const char *base64CmsSig;
success = FALSE;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
crypt = CkCrypt2_Create();
// Create the hash to be signed...
CkCrypt2_putHashAlgorithm(crypt,"sha256");
CkCrypt2_putEncodingMode(crypt,"base64");
CkCrypt2_putCharset(crypt,"utf-8");
// Create the SHA256 hash of a string using the utf-8 byte representation.
// Return the hash as base64.
base64Hash = CkCrypt2_hashStringENC(crypt,"This is the string to be hashed");
// Load a certificate for signing.
cert = CkCert_Create();
success = CkCert_LoadPfxFile(cert,"qa_data/pfx/cert_test123.pfx","test123");
if (success == FALSE) {
printf("%s\n",CkCert_lastErrorText(cert));
CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);
return;
}
CkCrypt2_SetSigningCert(crypt,cert);
// Sign the hash to create a base64 CMS signature (which does not contain the original data).
// We can get the signature in a single line of base64 by specifying "base64", or
// we can get multi-line base64 by specifying "base64_mime".
CkCrypt2_putEncodingMode(crypt,"base64_mime");
base64CmsSig = CkCrypt2_signHashENC(crypt,base64Hash,"sha256","base64");
if (CkCrypt2_getLastMethodSuccess(crypt) == FALSE) {
printf("%s\n",CkCrypt2_lastErrorText(crypt));
CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);
return;
}
// Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
// However, the encoding of the passed-in hash is indicated by the 3rd argument.
printf("CMS Signature: %s\n",base64CmsSig);
CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);
}