Sample code for 30+ languages & platforms
PureBasic

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkCrypt2.pb"
IncludeFile "CkCert.pb"

Procedure ChilkatExample()

    success.i = 0

    ; This example requires the Chilkat API to have been previously unlocked.
    ; See Global Unlock Sample for sample code.

    crypt.i = CkCrypt2::ckCreate()
    If crypt.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ; Create the hash to be signed...
    CkCrypt2::setCkHashAlgorithm(crypt, "sha256")
    CkCrypt2::setCkEncodingMode(crypt, "base64")
    CkCrypt2::setCkCharset(crypt, "utf-8")
    ; Create the SHA256 hash of a string using the utf-8 byte representation.
    ; Return the hash as base64.
    base64Hash.s = CkCrypt2::ckHashStringENC(crypt,"This is the string to be hashed")

    ; Load a certificate for signing.
    cert.i = CkCert::ckCreate()
    If cert.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    success = CkCert::ckLoadPfxFile(cert,"qa_data/pfx/cert_test123.pfx","test123")
    If success = 0
        Debug CkCert::ckLastErrorText(cert)
        CkCrypt2::ckDispose(crypt)
        CkCert::ckDispose(cert)
        ProcedureReturn
    EndIf

    CkCrypt2::ckSetSigningCert(crypt,cert)

    ; Sign the hash to create a base64 CMS signature (which does not contain the original data).
    ; We can get the signature in a single line of base64 by specifying "base64", or 
    ; we can get multi-line base64 by specifying "base64_mime".
    CkCrypt2::setCkEncodingMode(crypt, "base64_mime")
    base64CmsSig.s = CkCrypt2::ckSignHashENC(crypt,base64Hash,"sha256","base64")
    If CkCrypt2::ckLastMethodSuccess(crypt) = 0
        Debug CkCrypt2::ckLastErrorText(crypt)
        CkCrypt2::ckDispose(crypt)
        CkCert::ckDispose(cert)
        ProcedureReturn
    EndIf

    ; Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
    ; However, the encoding of the passed-in hash is indicated by the 3rd argument.

    Debug "CMS Signature: " + base64CmsSig


    CkCrypt2::ckDispose(crypt)
    CkCert::ckDispose(cert)


    ProcedureReturn
EndProcedure