Sample code for 30+ languages & platforms
AutoIt

Sign String to create a CAdES-T Signature, using HTTP Proxy to Access Timestamp Server

This example will sign a string to create a CAdEST-T signature. It will use an HTTP proxy to access the timestamp server.

Chilkat AutoIt Downloads

AutoIt
Local $bSuccess = False

$oCrypt = ObjCreate("Chilkat.Crypt2")

$oCert = ObjCreate("Chilkat.Cert")
$oCert.SmartCardPin = "123456"
$bSuccess = $oCert.LoadFromSmartcard("")
If ($bSuccess <> True) Then
    ConsoleWrite($oCert.LastErrorText & @CRLF)
    Exit
EndIf

$bSuccess = $oCrypt.SetSigningCert($oCert)

; Use SHA-256 rather than the default of SHA-1
$oCrypt.HashAlgorithm = "sha256"

; Create JSON that tells Chilkat what signing attributes to include:
$oAttrs = ObjCreate("Chilkat.JsonObject")
$oAttrs.UpdateBool("contentType",True)
$oAttrs.UpdateBool("signingTime",True)
$oAttrs.UpdateBool("messageDigest",True)
$oAttrs.UpdateBool("signingCertificateV2",True)

; A CAdES-T signature is one that includes a timestampToken created by an online TSA (time stamping authority).
; We must include the TSA's URL, as well as a few options to indicate what is desired.
; Except for the TSA URL, the options shown here are typically what you would need.
$oAttrs.UpdateBool("timestampToken.enabled",True)
$oAttrs.UpdateString("timestampToken.tsaUrl","https://freetsa.org/tsr")
$oAttrs.UpdateBool("timestampToken.addNonce",False)
$oAttrs.UpdateBool("timestampToken.requestTsaCert",True)
$oAttrs.UpdateString("timestampToken.hashAlg","sha256")

$oCrypt.SigningAttributes = $oAttrs.Emit()

Local $strToSign = "Hello World!"

$oBd = ObjCreate("Chilkat.BinData")
$oBd.AppendString($strToSign,"utf-8")

; -------------------------------------------------------------------------
; The purpose of this example is to show how an HTTP object with custom
; settings can be used to access the Internet when signing.
; Access to the Internet is needed to communicate with the timestamp server.
$oHttp = ObjCreate("Chilkat.Http")
; This can be a domain name, hostname, or IP address.
$oHttp.ProxyDomain = "172.16.16.56"
$oHttp.ProxyPort = 808
$oHttp.ProxyLogin = "myProxyLogin"
$oHttp.ProxyPassword = "myProxyPassword"
$oCrypt.SetTsaHttpObj $oHttp
; -------------------------------------------------------------------------

; This creates the CAdES-T signature.  During the signature creation, it
; communicates with the TSA to get a timestampToken.
; The contents of bd are signed and replaced with the CAdES-T signature (which embeds the original content).
$bSuccess = $oCrypt.OpaqueSignBd($oBd)
If ($bSuccess <> True) Then
    ConsoleWrite($oCrypt.LastErrorText & @CRLF)
    Exit
EndIf

; Get the signature in base64 format:
ConsoleWrite($oBd.GetEncoded("base64_mime") & @CRLF)

ConsoleWrite("Success." & @CRLF)