Objective-C
Objective-C
Sign JSON (or any Text) to Create a Detached PKCS7 Signature
Demonstrates how to sign JSON or any string using a certificate + private key from a .p12/.pfx to create a detached PKCS7 signature. (A detached signature is one that does not embed the original signed data.)Chilkat Objective-C Downloads
#import <CkoCrypt2.h>
#import <CkoCert.h>
#import <NSString.h>
BOOL success = NO;
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
CkoCrypt2 *crypt = [[CkoCrypt2 alloc] init];
CkoCert *cert = [[CkoCert alloc] init];
success = [cert LoadPfxFile: @"qa_data/pfx/cert_test123.pfx" password: @"test123"];
if (success != YES) {
NSLog(@"%@",cert.LastErrorText);
return;
}
// Tell the crypt component to use this cert.
success = [crypt SetSigningCert: cert];
if (success != YES) {
NSLog(@"%@",crypt.LastErrorText);
return;
}
crypt.HashAlgorithm = @"sha256";
// By default, all the certs in the chain of authentication are included in the signature.
// If desired, we can choose to only include the signing certificate:
crypt.IncludeCertChain = NO;
// Create the detached signature, which does NOT contain the original data.
// To create a PKCS7 signature that contains the original data, see CAdES Sign JSON
crypt.Charset = @"utf-8";
NSData detachedSig;
NSString *stringToSign = @"{ \"abc\": 123}";
detachedSig = [crypt SignString: stringToSign];
if (crypt.LastMethodSuccess == NO) {
NSLog(@"%@",crypt.LastErrorText);
return;
}
// Verify the signature against the original data.
BOOL verified = [crypt VerifyString: stringToSign sigData: detachedSig];
if (verified == NO) {
NSLog(@"%@",crypt.LastErrorText);
return;
}
NSLog(@"%@",@"Success!");