PHP Extension
PHP Extension
Create CAdES-BES .p7m using Smart Card or USB Token
See more Digital Signatures Examples
Demonstrates how to create a CAdES BES invoice.xml.p7m using a certificate stored on a smart card or USB token.Note: This example requires Chilkat v9.5.0.77 and at the time of this writing is restricted to the Windows operating system.
Chilkat PHP Extension Downloads
<?php
include("chilkat.php");
$success = false;
// Note: Requires Chilkat v9.5.0.77 or greater.
// This requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
$crypt = new CkCrypt2();
// Use a certificate on a smartcard or USB token.
$cert = new CkCert();
// Load the certificate on the smartcard currently in the reader (or on the USB token).
// Pass an empty string to allow Chilkat to automatically choose the CSP (Cryptographi Service Provider).
// See Load Certificate on Smartcard for information about explicitly selecting a particular CSP.
$success = $cert->LoadFromSmartcard('');
if ($success != true) {
print $cert->lastErrorText() . "\n";
exit;
}
// Provide the smartcard PIN.
// If the PIN is not explicitly provided here, the Windows OS should
// display a dialog for the PIN.
$cert->put_SmartCardPin('000000');
// Provide the certificate for signing.
$success = $crypt->SetSigningCert($cert);
if ($success != true) {
print $crypt->lastErrorText() . "\n";
exit;
}
// Indicate that SHA-256 should be used.
$crypt->put_HashAlgorithm('sha256');
// Specify the signed attributes to be included.
// (This is what makes it CAdES-BES compliant.)
$jsonSignedAttrs = new CkJsonObject();
$jsonSignedAttrs->UpdateInt('contentType',1);
$jsonSignedAttrs->UpdateInt('signingTime',1);
$jsonSignedAttrs->UpdateInt('messageDigest',1);
$jsonSignedAttrs->UpdateInt('signingCertificateV2',1);
$crypt->put_SigningAttributes($jsonSignedAttrs->emit());
$inFile = 'qa_data/xml/IT01234567890_11002.xml';
$sigFile = 'qa_output/IT01234567890_11002.xml.p7m';
// Create the CAdES-BES signature, which contains the original data.
$success = $crypt->CreateP7M($inFile,$sigFile);
if ($success == false) {
print $crypt->lastErrorText() . "\n";
exit;
}
print 'Success.' . "\n";
?>