Sample code for 30+ languages & platforms
Delphi DLL

Create .p7s using Smart Card or USB Token

Demonstrates how to create a .p7s using a certificate stored on a smart card or USB token.

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Cert, JsonObject, Crypt2;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
crypt: HCkCrypt2;
cert: HCkCert;
jsonSignedAttrs: HCkJsonObject;
inFile: PWideChar;
sigFile: PWideChar;

begin
success := False;

// This requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

crypt := CkCrypt2_Create();

// Use a certificate on a smartcard or USB token.
cert := CkCert_Create();

// Provide the smartcard PIN.
CkCert_putSmartCardPin(cert,'000000');

// Load the certificate on the smartcard currently in the reader (or on the USB token).
success := CkCert_LoadFromSmartcard(cert,'');
if (success <> True) then
  begin
    Memo1.Lines.Add(CkCert__lastErrorText(cert));
    Exit;
  end;

// Provide the certificate for signing.
success := CkCrypt2_SetSigningCert(crypt,cert);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkCrypt2__lastErrorText(crypt));
    Exit;
  end;

// Indicate that SHA-256 should be used.
CkCrypt2_putHashAlgorithm(crypt,'sha256');

// Specify the signed attributes to be included.
jsonSignedAttrs := CkJsonObject_Create();
CkJsonObject_UpdateInt(jsonSignedAttrs,'contentType',1);
CkJsonObject_UpdateInt(jsonSignedAttrs,'signingTime',1);
CkJsonObject_UpdateInt(jsonSignedAttrs,'messageDigest',1);
CkJsonObject_UpdateInt(jsonSignedAttrs,'signingCertificateV2',1);
CkCrypt2_putSigningAttributes(crypt,CkJsonObject__emit(jsonSignedAttrs));

inFile := 'qa_data/xml/IT01234567890_11002.xml';
sigFile := 'qa_output/IT01234567890_11002.xml.p7s';

// Create the .p7s, which is a signature file that does not embed the original data.
// (To create a signature file that also embeds the original data, call CreateP7M instead)
success := CkCrypt2_CreateP7S(crypt,inFile,sigFile);
if (success = False) then
  begin
    Memo1.Lines.Add(CkCrypt2__lastErrorText(crypt));
    Exit;
  end;

Memo1.Lines.Add('Success.');

CkCrypt2_Dispose(crypt);
CkCert_Dispose(cert);
CkJsonObject_Dispose(jsonSignedAttrs);

end;