Sample code for 30+ languages & platforms
Lazarus Pascal

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Lazarus Pascal Downloads

Lazarus Pascal
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.Cert,
  Chilkat.Crypt2;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  crypt: TCrypt2;
  base64Hash: string;
  cert: TCert;
  base64CmsSig: string;

begin
  success := False;

  //  This example requires the Chilkat API to have been previously unlocked.
  //  See Global Unlock Sample for sample code.

  crypt := TCrypt2.Create;

  //  Create the hash to be signed...
  crypt.HashAlgorithm := 'sha256';
  crypt.EncodingMode := 'base64';
  crypt.Charset := 'utf-8';
  //  Create the SHA256 hash of a string using the utf-8 byte representation.
  //  Return the hash as base64.
  base64Hash := crypt.HashStringENC('This is the string to be hashed');

  //  Load a certificate for signing.
  cert := TCert.Create;
  success := cert.LoadPfxFile('qa_data/pfx/cert_test123.pfx','test123');
  if (success = False) then
    begin
      WriteLn(cert.LastErrorText);
      Exit;
    end;
  crypt.SetSigningCert(cert);

  //  Sign the hash to create a base64 CMS signature (which does not contain the original data).
  //  We can get the signature in a single line of base64 by specifying "base64", or 
  //  we can get multi-line base64 by specifying "base64_mime".
  crypt.EncodingMode := 'base64_mime';
  base64CmsSig := crypt.SignHashENC(base64Hash,'sha256','base64');
  if (crypt.LastMethodSuccess = False) then
    begin
      WriteLn(crypt.LastErrorText);
      Exit;
    end;

  //  Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
  //  However, the encoding of the passed-in hash is indicated by the 3rd argument.

  WriteLn('CMS Signature: ' + base64CmsSig);


  crypt.Free;
  cert.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.