Sample code for 30+ languages & platforms
Delphi DLL

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Cert, Crypt2;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
crypt: HCkCrypt2;
base64Hash: PWideChar;
cert: HCkCert;
base64CmsSig: PWideChar;

begin
success := False;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

crypt := CkCrypt2_Create();

// Create the hash to be signed...
CkCrypt2_putHashAlgorithm(crypt,'sha256');
CkCrypt2_putEncodingMode(crypt,'base64');
CkCrypt2_putCharset(crypt,'utf-8');
// Create the SHA256 hash of a string using the utf-8 byte representation.
// Return the hash as base64.
base64Hash := CkCrypt2__hashStringENC(crypt,'This is the string to be hashed');

// Load a certificate for signing.
cert := CkCert_Create();
success := CkCert_LoadPfxFile(cert,'qa_data/pfx/cert_test123.pfx','test123');
if (success = False) then
  begin
    Memo1.Lines.Add(CkCert__lastErrorText(cert));
    Exit;
  end;
CkCrypt2_SetSigningCert(crypt,cert);

// Sign the hash to create a base64 CMS signature (which does not contain the original data).
// We can get the signature in a single line of base64 by specifying "base64", or 
// we can get multi-line base64 by specifying "base64_mime".
CkCrypt2_putEncodingMode(crypt,'base64_mime');
base64CmsSig := CkCrypt2__signHashENC(crypt,base64Hash,'sha256','base64');
if (CkCrypt2_getLastMethodSuccess(crypt) = False) then
  begin
    Memo1.Lines.Add(CkCrypt2__lastErrorText(crypt));
    Exit;
  end;

// Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
// However, the encoding of the passed-in hash is indicated by the 3rd argument.

Memo1.Lines.Add('CMS Signature: ' + base64CmsSig);

CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);

end;