Sample code for 30+ languages & platforms
B4X

Verify XML Signature with External URL References

See more XML Digital Signatures Examples

Demonstrates how to verify an XML digital signature that includes references to URLs where the data to be digested is on a web server.

Chilkat B4X Downloads

B4X
Dim success As Boolean = False

'  This example requires the Chilkat API to have been previously unlocked.
'  See Global Unlock Sample for sample code.

'  The signed XML we wish to verify contains external references such as this:

'      <ds:Reference Id="xmldsig-e7ae7ce2-9133-4d56-bd97-0a6aef738cc2-ref0" URI="https://www.chilkatsoft.com/images/starfish.jpg">
'        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
'        <ds:DigestValue>AOU810yJV5Np/DnO29qpObqiTSTTCDvxGsX5ayiTYXI=</ds:DigestValue>
'      </ds:Reference>
'      <ds:Reference Id="xmldsig-e7ae7ce2-9133-4d56-bd97-0a6aef738cc2-ref1" URI="https://www.chilkatsoft.com/hamlet.xml">
'        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
'        <ds:DigestValue>4sRRyWOzC7EOic4fQ9+Op1pa10DbgoBGjBvkq09LZmE=</ds:DigestValue>
'      </ds:Reference>

Dim verifier As ChilkatXmlDSig
verifier.Initialize
Dim http As ChilkatHttp
http.Initialize("http")

'  First load the signed XML
Dim sbSignedXml As ChilkatStringBuilder
sbSignedXml.Initialize
success = sbSignedXml.LoadFile("qa_data/xml_dsig_verify/signedWithExternalUrlRefs.xml", "utf-8")
If success = False Then
    Log("Failed to load signed XML.")
    Return
End If


success = verifier.LoadSignatureSb(sbSignedXml)
If success = False Then
    Log(verifier.LastErrorText)
    Return
End If


'  Iterate over each reference.  If it is an external URL reference, download the data and provide it to the verifier.
Dim sbRefUri As ChilkatStringBuilder
sbRefUri.Initialize
Dim bd As ChilkatBinData
bd.Initialize
Dim numRefs As Int = verifier.NumReferences
Dim i As Int = 0
Do While i < numRefs
    If verifier.IsReferenceExternal(i) = True Then
        sbRefUri.Clear
        sbRefUri.Append(verifier.ReferenceUri(i))
        If sbRefUri.StartsWith("https://", False) = True Then
            Log("External URL Reference: " & sbRefUri.GetAsString)

            '  Download the data at the URL and provide to the verifier.
            success = http.DownloadBd(sbRefUri.GetAsString, bd)
            If success = False Then
                Log(http.LastErrorText)
                Return
            End If

            success = verifier.SetRefDataBd(i, bd)
            If success = False Then
                Log(verifier.LastErrorText)
                Return
            End If

        End If

    End If

    i = i + 1
Loop

'  Now that we have the external data, verify the signature..
Dim bVerified As Boolean = verifier.VerifySignature(True)
If bVerified = False Then
    Log(verifier.LastErrorText)
End If

Log("Signature verified = " & bVerified)