Sample code for 30+ languages & platforms
Rust

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

let crypt = chilkat::Crypt2::new();

// Create the hash to be signed...
crypt.set_hash_algorithm("sha256");
crypt.set_encoding_mode("base64");
crypt.set_charset("utf-8");
// Create the SHA256 hash of a string using the utf-8 byte representation.
// Return the hash as base64.
let base64_hash = crypt.hash_string_enc("This is the string to be hashed").unwrap_or_default();

// Load a certificate for signing.
let cert = chilkat::Cert::new();
if cert.load_pfx_file("qa_data/pfx/cert_test123.pfx", "test123").is_err() {
    println!("{}", cert.last_error_text());
    return;
}

let _ = crypt.set_signing_cert(&cert);

// Sign the hash to create a base64 CMS signature (which does not contain the original data).
// We can get the signature in a single line of base64 by specifying "base64", or 
// we can get multi-line base64 by specifying "base64_mime".
crypt.set_encoding_mode("base64_mime");
let Ok(base64_cms_sig) = crypt.sign_hash_enc(&base64_hash, "sha256", "base64") else {
    println!("{}", crypt.last_error_text());
    return;
};

// Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
// However, the encoding of the passed-in hash is indicated by the 3rd argument.

println!("CMS Signature: {}", base64_cms_sig);