Sample code for 30+ languages & platforms
Delphi DLL

Sign String to create a CAdES-T Signature, using HTTP Proxy to Access Timestamp Server

This example will sign a string to create a CAdEST-T signature. It will use an HTTP proxy to access the timestamp server.

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Http, BinData, Cert, JsonObject, Crypt2;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
crypt: HCkCrypt2;
cert: HCkCert;
attrs: HCkJsonObject;
strToSign: PWideChar;
bd: HCkBinData;
http: HCkHttp;

begin
success := False;

crypt := CkCrypt2_Create();

cert := CkCert_Create();
CkCert_putSmartCardPin(cert,'123456');
success := CkCert_LoadFromSmartcard(cert,'');
if (success <> True) then
  begin
    Memo1.Lines.Add(CkCert__lastErrorText(cert));
    Exit;
  end;

success := CkCrypt2_SetSigningCert(crypt,cert);

// Use SHA-256 rather than the default of SHA-1
CkCrypt2_putHashAlgorithm(crypt,'sha256');

// Create JSON that tells Chilkat what signing attributes to include:
attrs := CkJsonObject_Create();
CkJsonObject_UpdateBool(attrs,'contentType',True);
CkJsonObject_UpdateBool(attrs,'signingTime',True);
CkJsonObject_UpdateBool(attrs,'messageDigest',True);
CkJsonObject_UpdateBool(attrs,'signingCertificateV2',True);

// A CAdES-T signature is one that includes a timestampToken created by an online TSA (time stamping authority).
// We must include the TSA's URL, as well as a few options to indicate what is desired.
// Except for the TSA URL, the options shown here are typically what you would need.
CkJsonObject_UpdateBool(attrs,'timestampToken.enabled',True);
CkJsonObject_UpdateString(attrs,'timestampToken.tsaUrl','https://freetsa.org/tsr');
CkJsonObject_UpdateBool(attrs,'timestampToken.addNonce',False);
CkJsonObject_UpdateBool(attrs,'timestampToken.requestTsaCert',True);
CkJsonObject_UpdateString(attrs,'timestampToken.hashAlg','sha256');

CkCrypt2_putSigningAttributes(crypt,CkJsonObject__emit(attrs));

strToSign := 'Hello World!';

bd := CkBinData_Create();
CkBinData_AppendString(bd,strToSign,'utf-8');

// -------------------------------------------------------------------------
// The purpose of this example is to show how an HTTP object with custom
// settings can be used to access the Internet when signing.
// Access to the Internet is needed to communicate with the timestamp server.
http := CkHttp_Create();
// This can be a domain name, hostname, or IP address.
CkHttp_putProxyDomain(http,'172.16.16.56');
CkHttp_putProxyPort(http,808);
CkHttp_putProxyLogin(http,'myProxyLogin');
CkHttp_putProxyPassword(http,'myProxyPassword');
CkCrypt2_SetTsaHttpObj(crypt,http);
// -------------------------------------------------------------------------

// This creates the CAdES-T signature.  During the signature creation, it
// communicates with the TSA to get a timestampToken.
// The contents of bd are signed and replaced with the CAdES-T signature (which embeds the original content).
success := CkCrypt2_OpaqueSignBd(crypt,bd);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkCrypt2__lastErrorText(crypt));
    Exit;
  end;

// Get the signature in base64 format:
Memo1.Lines.Add(CkBinData__getEncoded(bd,'base64_mime'));

Memo1.Lines.Add('Success.');

CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);
CkJsonObject_Dispose(attrs);
CkBinData_Dispose(bd);
CkHttp_Dispose(http);

end;