Sample code for 30+ languages & platforms
Visual FoxPro

Sign JSON (or any Text) to Create a Detached PKCS7 Signature

Demonstrates how to sign JSON or any string using a certificate + private key from a .p12/.pfx to create a detached PKCS7 signature. (A detached signature is one that does not embed the original signed data.)

Chilkat Visual FoxPro Downloads

Visual FoxPro
LOCAL lnSuccess
LOCAL loCrypt
LOCAL loCert
LOCAL loDetachedSig
LOCAL lcStringToSign
LOCAL lnVerified

lnSuccess = 0

* This example assumes the Chilkat API to have been previously unlocked.
* See Global Unlock Sample for sample code.

loCrypt = CreateObject('Chilkat.Crypt2')

loCert = CreateObject('Chilkat.Cert')
lnSuccess = loCert.LoadPfxFile("qa_data/pfx/cert_test123.pfx","test123")
IF (lnSuccess <> 1) THEN
    ? loCert.LastErrorText
    RELEASE loCrypt
    RELEASE loCert
    CANCEL
ENDIF

* Tell the crypt component to use this cert.
lnSuccess = loCrypt.SetSigningCert(loCert)
IF (lnSuccess <> 1) THEN
    ? loCrypt.LastErrorText
    RELEASE loCrypt
    RELEASE loCert
    CANCEL
ENDIF

loCrypt.HashAlgorithm = "sha256"

* By default, all the certs in the chain of authentication are included in the signature.
* If desired, we can choose to only include the signing certificate:
loCrypt.IncludeCertChain = 0

* Create the detached signature, which does NOT contain the original data.
* To create a PKCS7 signature that contains the original data, see CAdES Sign JSON
loCrypt.Charset = "utf-8"

lcStringToSign = '{ "abc": 123}'
loDetachedSig = loCrypt.SignString(lcStringToSign)
IF (loCrypt.LastMethodSuccess = 0) THEN
    ? loCrypt.LastErrorText
    RELEASE loCrypt
    RELEASE loCert
    CANCEL
ENDIF

* Verify the signature against the original data.
lnVerified = loCrypt.VerifyString(lcStringToSign,loDetachedSig)
IF (lnVerified = 0) THEN
    ? loCrypt.LastErrorText
    RELEASE loCrypt
    RELEASE loCert
    CANCEL
ENDIF

? "Success!"

RELEASE loCrypt
RELEASE loCert