Sample code for 30+ languages & platforms
Dart

FatturaPA XML Invoice Sign+Encrypt to P7M

See more Digital Signatures Examples

Demonstrates how to create a CAdES BES signed + encrypted invoice.xml.p7m for the Italian FatturaPA exchange system.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final crypt = CkCrypt2();

  // Use a digital certificate and private key from a PFX file (.pfx or .p12).
  final pfxPath = 'qa_data/pfx/cert_test123.pfx';
  final pfxPassword = 'test123';

  final cert = CkCert();
  try {
    cert.loadPfxFile(pfxPath, pfxPassword);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Provide the signing cert (with associated private key).
  try {
    crypt.setSigningCert(cert);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Indicate that SHA-256 should be used.
  crypt.hashAlgorithm = 'sha256';

  // Specify the signed attributes to be included.
  // (This is what makes it CAdES-BES compliant.)
  final jsonSignedAttrs = CkJsonObject();
  jsonSignedAttrs.updateInt('contentType', 1);
  jsonSignedAttrs.updateInt('signingTime', 1);
  jsonSignedAttrs.updateInt('messageDigest', 1);
  jsonSignedAttrs.updateInt('signingCertificateV2', 1);
  crypt.signingAttributes = jsonSignedAttrs.emit();

  final inFile = 'qa_data/xml/IT01234567890_11002.xml';
  final sigFile = 'qa_data/fatturapa/signed.p7m';

  // Create the CAdES-BES signature, which contains the original data.
  try {
    crypt.createP7M(inFile, sigFile);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Now we'll encrypt what was signed using FatturaPA's certificate (from a PEM file)
  final encryptCert = CkCert();
  try {
    encryptCert.loadFromFile('qa_data/certs/fatturapa_cert.pem');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  crypt.cryptAlgorithm = 'pki';

  try {
    crypt.setEncryptCert(encryptCert);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Indicate the underlying bulk encryption algorithm to be used:
  crypt.pkcs7CryptAlg = 'aes';
  crypt.keyLength = 128;

  // There's one last option that could be set.  If is the RSA encryption encryption/padding scheme. 
  // By default, RSAES_PKCS1-V1_5 is used.  If desired, the OaepPadding property could be set to true to
  // use RSAES_OAEP.  (We'll leave it set at the default value of false)
  crypt.oaepPadding = false;

  // Everything is specified.  Encrypt the .p7m to create a new .p7m (which adds a layer of encryption around the opaque signature).
  // The output is PKCS7 in binary DER format.
  try {
    crypt.ckEncryptFile(sigFile, 'qa_output/signed_and_encrypted.p7m');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('Success.');
}