Lazarus Pascal
Lazarus Pascal
Sign String to create a CAdES-T Signature, using HTTP Proxy to Access Timestamp Server
This example will sign a string to create a CAdEST-T signature. It will use an HTTP proxy to access the timestamp server.Chilkat Lazarus Pascal Downloads
program ChilkatDemo;
// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.
{$IFDEF FPC}
{$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}
uses
{$IFDEF UNIX}
cthreads,
{$ENDIF}
SysUtils,
CkDllLoader,
Chilkat.Http,
Chilkat.BinData,
Chilkat.Cert,
Chilkat.JsonObject,
Chilkat.Crypt2;
// ---------------------------------------------------------------------------
procedure RunDemo;
var
success: Boolean;
crypt: TCrypt2;
cert: TCert;
attrs: TJsonObject;
strToSign: string;
bd: TBinData;
http: THttp;
begin
success := False;
crypt := TCrypt2.Create;
cert := TCert.Create;
cert.SmartCardPin := '123456';
success := cert.LoadFromSmartcard('');
if (success <> True) then
begin
WriteLn(cert.LastErrorText);
Exit;
end;
success := crypt.SetSigningCert(cert);
// Use SHA-256 rather than the default of SHA-1
crypt.HashAlgorithm := 'sha256';
// Create JSON that tells Chilkat what signing attributes to include:
attrs := TJsonObject.Create;
attrs.UpdateBool('contentType',True);
attrs.UpdateBool('signingTime',True);
attrs.UpdateBool('messageDigest',True);
attrs.UpdateBool('signingCertificateV2',True);
// A CAdES-T signature is one that includes a timestampToken created by an online TSA (time stamping authority).
// We must include the TSA's URL, as well as a few options to indicate what is desired.
// Except for the TSA URL, the options shown here are typically what you would need.
attrs.UpdateBool('timestampToken.enabled',True);
attrs.UpdateString('timestampToken.tsaUrl','https://freetsa.org/tsr');
attrs.UpdateBool('timestampToken.addNonce',False);
attrs.UpdateBool('timestampToken.requestTsaCert',True);
attrs.UpdateString('timestampToken.hashAlg','sha256');
crypt.SigningAttributes := attrs.Emit();
strToSign := 'Hello World!';
bd := TBinData.Create;
bd.AppendString(strToSign,'utf-8');
// -------------------------------------------------------------------------
// The purpose of this example is to show how an HTTP object with custom
// settings can be used to access the Internet when signing.
// Access to the Internet is needed to communicate with the timestamp server.
http := THttp.Create;
// This can be a domain name, hostname, or IP address.
http.ProxyDomain := '172.16.16.56';
http.ProxyPort := 808;
http.ProxyLogin := 'myProxyLogin';
http.ProxyPassword := 'myProxyPassword';
crypt.SetTsaHttpObj(http);
// -------------------------------------------------------------------------
// This creates the CAdES-T signature. During the signature creation, it
// communicates with the TSA to get a timestampToken.
// The contents of bd are signed and replaced with the CAdES-T signature (which embeds the original content).
success := crypt.OpaqueSignBd(bd);
if (success <> True) then
begin
WriteLn(crypt.LastErrorText);
Exit;
end;
// Get the signature in base64 format:
WriteLn(bd.GetEncoded('base64_mime'));
WriteLn('Success.');
crypt.Free;
cert.Free;
attrs.Free;
bd.Free;
http.Free;
end;
// ---------------------------------------------------------------------------
begin
try
RunDemo;
except
on E: Exception do
WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
end;
WriteLn;
{$IFDEF MSWINDOWS}
WriteLn('Press Enter to exit...');
ReadLn;
{$ENDIF}
end.