Sample code for 30+ languages & platforms
Classic ASP

XML-DSig Add Object Reference with Transforms Specified Explicitly

Demonstrates how to use the new AddObjectRef2 method to explicitly specify the XML Transforms fragment.

Chilkat Classic ASP Downloads

Classic ASP
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<%
success = 0

' This example requires the Chilkat API to have been previously unlocked.
' See Global Unlock Sample for sample code.

success = 1

' Build the following XML to be signed:

' <?xml version="1.0" encoding="utf-8"?>
' <InitUpload xmlns="http://e-dokumenty.mf.gov.pl">
'     <DocumentType>JPK</DocumentType>
'     <Version>01.02.01.20160617</Version>
'     <EncryptionKey algorithm="RSA" encoding="Base64" mode="ECB" padding="PKCS#1">xxxx</EncryptionKey>
'     <DocumentList>
'         <Document>
'             <FormCode schemaVersion="1-1" systemCode="JPK_VAT (3)">JPK_VAT</FormCode>
'             <FileName>JPK_VAT_3_v1-1_20181201.xml</FileName>
'             <ContentLength>8736</ContentLength>
'             <HashValue algorithm="SHA-256" encoding="Base64">JEDI1pItwh6dj/Xx1uts/x61qnjZ4DLHpkZMhmf1oKQ=</HashValue>
'             <FileSignatureList filesNumber="1">
'                 <Packaging>
'                     <SplitZip mode="zip" type="split"/>
'                 </Packaging>
'                 <Encryption>
'                     <AES block="16" mode="CBC" padding="PKCS#7" size="256">
'                         <IV bytes="16" encoding="Base64">z64oN9zXHt1+S3XACRSCYw==</IV>
'                     </AES>
'                 </Encryption>
'                 <FileSignature>
'                     <OrdinalNumber>1</OrdinalNumber>
'                     <FileName>JPK_VAT_3_v1-1_20181201-000.xml.zip.aes</FileName>
'                     <ContentLength>16</ContentLength>
'                     <HashValue algorithm="MD5" encoding="Base64">5MX0q1935fvMjLFV7E1yDw==</HashValue>
'                 </FileSignature>
'             </FileSignatureList>
'         </Document>
'     </DocumentList>
' </InitUpload>

' Use this online tool to generate code from sample XML: 
' Generate Code to Create XML

set xmlToSign = Server.CreateObject("Chilkat.Xml")
xmlToSign.Tag = "InitUpload"
success = xmlToSign.AddAttribute("xmlns","http://e-dokumenty.mf.gov.pl")
xmlToSign.UpdateChildContent "DocumentType","JPK"
xmlToSign.UpdateChildContent "Version","01.02.01.20160617"
success = xmlToSign.UpdateAttrAt("EncryptionKey",1,"algorithm","RSA")
success = xmlToSign.UpdateAttrAt("EncryptionKey",1,"encoding","Base64")
success = xmlToSign.UpdateAttrAt("EncryptionKey",1,"mode","ECB")
success = xmlToSign.UpdateAttrAt("EncryptionKey",1,"padding","PKCS#1")
xmlToSign.UpdateChildContent "EncryptionKey","xxxx"
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FormCode",1,"schemaVersion","1-1")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FormCode",1,"systemCode","JPK_VAT (3)")
xmlToSign.UpdateChildContent "DocumentList|Document|FormCode","JPK_VAT"
xmlToSign.UpdateChildContent "DocumentList|Document|FileName","JPK_VAT_3_v1-1_20181201.xml"
xmlToSign.UpdateChildContent "DocumentList|Document|ContentLength","8736"
success = xmlToSign.UpdateAttrAt("DocumentList|Document|HashValue",1,"algorithm","SHA-256")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|HashValue",1,"encoding","Base64")
xmlToSign.UpdateChildContent "DocumentList|Document|HashValue","JEDI1pItwh6dj/Xx1uts/x61qnjZ4DLHpkZMhmf1oKQ="
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList",1,"filesNumber","1")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip",1,"mode","zip")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip",1,"type","split")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES",1,"block","16")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES",1,"mode","CBC")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES",1,"padding","PKCS#7")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES",1,"size","256")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV",1,"bytes","16")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV",1,"encoding","Base64")
xmlToSign.UpdateChildContent "DocumentList|Document|FileSignatureList|Encryption|AES|IV","z64oN9zXHt1+S3XACRSCYw=="
xmlToSign.UpdateChildContent "DocumentList|Document|FileSignatureList|FileSignature|OrdinalNumber","1"
xmlToSign.UpdateChildContent "DocumentList|Document|FileSignatureList|FileSignature|FileName","JPK_VAT_3_v1-1_20181201-000.xml.zip.aes"
xmlToSign.UpdateChildContent "DocumentList|Document|FileSignatureList|FileSignature|ContentLength","16"
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue",1,"algorithm","MD5")
success = xmlToSign.UpdateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue",1,"encoding","Base64")
xmlToSign.UpdateChildContent "DocumentList|Document|FileSignatureList|FileSignature|HashValue","5MX0q1935fvMjLFV7E1yDw=="

set gen = Server.CreateObject("Chilkat.XmlDSigGen")

gen.SigLocation = "InitUpload"
gen.SigLocationMod = 0
gen.SigId = "id-1234"
gen.SigNamespacePrefix = "ds"
gen.SigNamespaceUri = "http://www.w3.org/2000/09/xmldsig#"
gen.SignedInfoCanonAlg = "EXCL_C14N"
gen.SignedInfoDigestMethod = "sha256"

' Create an Object to be added to the Signature.

' <xades:QualifyingProperties Target="#id-1234" xmlns:xades="http://uri.etsi.org/01903/v1.3.2#">
'     <xades:SignedProperties Id="xades-id-1234">
'         <xades:SignedSignatureProperties>
'             <xades:SigningTime>TO BE GENERATED BY CHILKAT</xades:SigningTime>
'             <xades:SigningCertificate>
'                 <xades:Cert>
'                     <xades:CertDigest>
'                         <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
'                         <ds:DigestValue>TO BE GENERATED BY CHILKAT</ds:DigestValue>
'                     </xades:CertDigest>
'                     <xades:IssuerSerial>
'                         <ds:X509IssuerName>TO BE GENERATED BY CHILKAT</ds:X509IssuerName>
'                         <ds:X509SerialNumber>TO BE GENERATED BY CHILKAT</ds:X509SerialNumber>
'                     </xades:IssuerSerial>
'                 </xades:Cert>
'             </xades:SigningCertificate>
'         </xades:SignedSignatureProperties>
'         <xades:SignedDataObjectProperties>
'             <xades:DataObjectFormat ObjectReference="#r-id-1">
'                 <xades:MimeType>text/xml</xades:MimeType>
'             </xades:DataObjectFormat>
'         </xades:SignedDataObjectProperties>
'     </xades:SignedProperties>
' </xades:QualifyingProperties>

set object1 = Server.CreateObject("Chilkat.Xml")
object1.Tag = "xades:QualifyingProperties"
success = object1.AddAttribute("xmlns:xades","http://uri.etsi.org/01903/v1.3.2#")
success = object1.AddAttribute("Target","#id-1234")
success = object1.UpdateAttrAt("xades:SignedProperties",1,"Id","xades-id-1234")
' Note: It may be that http://www.w3.org/2001/04/xmlenc#sha256 is needed in the following line instead of http://www.w3.org/2000/09/xmldsig#sha1
object1.UpdateChildContent "xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningTime","TO BE GENERATED BY CHILKAT"
success = object1.UpdateAttrAt("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestMethod",1,"Algorithm","http://www.w3.org/2000/09/xmldsig#sha1")
object1.UpdateChildContent "xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestValue","TO BE GENERATED BY CHILKAT"
object1.UpdateChildContent "xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:IssuerSerialV2","TO BE GENERATED BY CHILKAT"
success = object1.UpdateAttrAt("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat",1,"ObjectReference","#r-id-1")
object1.UpdateChildContent "xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:MimeType","text/xml"

success = gen.AddObject("",object1.GetXml(),"","")

' -------- Reference 1 --------
' Build the following Transforms fragment:

' <ds:Transforms>
'     <ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
'         <ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
'     </ds:Transform>
'     <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
' </ds:Transforms>

set xml1 = Server.CreateObject("Chilkat.Xml")
xml1.Tag = "ds:Transforms"
success = xml1.UpdateAttrAt("ds:Transform",1,"Algorithm","http://www.w3.org/TR/1999/REC-xpath-19991116")
xml1.UpdateChildContent "ds:Transform|ds:XPath","not(ancestor-or-self::ds:Signature)"
success = xml1.UpdateAttrAt("ds:Transform[1]",1,"Algorithm","http://www.w3.org/2001/10/xml-exc-c14n#")

success = gen.AddSameDocRef2("","sha256",xml1,"")
success = gen.SetRefIdAttr("","r-id-1")

' -------- Reference 2 --------
' Build the following Transforms fragment:

' <ds:Transforms>
'     <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
' </ds:Transforms>

set xml2 = Server.CreateObject("Chilkat.Xml")
xml2.Tag = "ds:Transforms"
success = xml2.UpdateAttrAt("ds:Transform",1,"Algorithm","http://www.w3.org/2001/10/xml-exc-c14n#")

success = gen.AddObjectRef2("xades-id-1234","sha256",xml2,"http://uri.etsi.org/01903#SignedProperties")

' Provide a certificate + private key. (PFX password is test123)
set cert = Server.CreateObject("Chilkat.Cert")
success = cert.LoadPfxFile("qa_data/pfx/cert_test123.pfx","test123")
If (success <> 1) Then
    Response.Write "<pre>" & Server.HTMLEncode( cert.LastErrorText) & "</pre>"
    Response.End
End If

success = gen.SetX509Cert(cert,1)

gen.KeyInfoType = "X509Data"
gen.X509Type = "Certificate"

' Load XML to be signed...
set sbXml = Server.CreateObject("Chilkat.StringBuilder")
success = xmlToSign.GetXmlSb(sbXml)

gen.Behaviors = "IndentedSignature"

' Sign the XML...
success = gen.CreateXmlDSigSb(sbXml)
If (success <> 1) Then
    Response.Write "<pre>" & Server.HTMLEncode( gen.LastErrorText) & "</pre>"
    Response.End
End If

' -----------------------------------------------

' Save the signed XML to a file.
success = sbXml.WriteFile("qa_output/signedXml.xml","utf-8",0)

Response.Write "<pre>" & Server.HTMLEncode( sbXml.GetAsString()) & "</pre>"

' ----------------------------------------
' Verify the signatures we just produced...
set verifier = Server.CreateObject("Chilkat.XmlDSig")
success = verifier.LoadSignatureSb(sbXml)
If (success <> 1) Then
    Response.Write "<pre>" & Server.HTMLEncode( verifier.LastErrorText) & "</pre>"
    Response.End
End If

numSigs = verifier.NumSignatures
verifyIdx = 0
Do While verifyIdx < numSigs
    verifier.Selector = verifyIdx
    verified = verifier.VerifySignature(1)
    If (verified <> 1) Then
        Response.Write "<pre>" & Server.HTMLEncode( verifier.LastErrorText) & "</pre>"
        Response.End
    End If

    verifyIdx = verifyIdx + 1
Loop
Response.Write "<pre>" & Server.HTMLEncode( "All signatures were successfully verified.") & "</pre>"

%>
</body>
</html>