Sample code for 30+ languages & platforms
C++

Sign JSON to Create CAdES P7S Bytes

See more CAdES Examples

Demonstrates how to sign JSON using a certificate + private key from a .p12/.pfx to create a CAdES P7S byte array.

Chilkat C++ Downloads

C++
#include <CkCrypt2.h>
#include <CkCert.h>
#include <CkJsonObject.h>
#include <CkByteData.h>

void ChilkatSample(void)
    {
    bool success = false;

    //  This example assumes the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    CkCrypt2 crypt;

    CkCert cert;
    success = cert.LoadPfxFile("qa_data/pfx/cert_test123.pfx","test123");
    if (success != true) {
        std::cout << cert.lastErrorText() << "\r\n";
        return;
    }

    //  Tell the crypt component to use this cert.
    success = crypt.SetSigningCert(cert);
    if (success != true) {
        std::cout << crypt.lastErrorText() << "\r\n";
        return;
    }

    //  The CadesEnabled property applies to all methods that create PKCS7 signatures. 
    //  To create a CAdES-BES signature, set this property equal to true. 
    crypt.put_CadesEnabled(true);

    crypt.put_HashAlgorithm("sha256");

    CkJsonObject jsonSigningAttrs;
    jsonSigningAttrs.UpdateInt("contentType",1);
    jsonSigningAttrs.UpdateInt("signingTime",1);
    jsonSigningAttrs.UpdateInt("messageDigest",1);
    jsonSigningAttrs.UpdateInt("signingCertificateV2",1);
    crypt.put_SigningAttributes(jsonSigningAttrs.emit());

    //  By default, all the certs in the chain of authentication are included in the signature.
    //  If desired, we can choose to only include the signing certificate:
    crypt.put_IncludeCertChain(false);

    //  Create the CAdES-BES attached signature, which contains the original data.
    crypt.put_Charset("utf-8");
    CkByteData cadesP7s;
    success = crypt.OpaqueSignString("{ \"abc\": 123}",cadesP7s);
    if (crypt.get_LastMethodSuccess() == false) {
        std::cout << crypt.lastErrorText() << "\r\n";
        return;
    }

    //  Verify the signature and extract the original JSON:
    const char *originalJson = crypt.opaqueVerifyString(cadesP7s);
    if (crypt.get_LastMethodSuccess() == false) {
        std::cout << crypt.lastErrorText() << "\r\n";
        return;
    }

    std::cout << "Original JSON: " << originalJson << "\r\n";

    std::cout << "Success!" << "\r\n";
    }