Sample code for 30+ languages & platforms
Rust

Sign a PDF using SmartCard or HSM (Hardware Security Module)

See more PDF Signatures Examples

This example demonstrates how to a sign a PDF using a smartcard or HSM (hardware security module).

Note: This example requires Chilkat v9.5.0.88 or greater.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

let pdf = chilkat::Pdf::new();

// Load a PDF to be signed.
// The "hello.pdf" is available at https://chilkatsoft.com/hello.pdf
if pdf.load_file("qa_data/pdf/hello.pdf").is_err() {
    println!("{}", pdf.last_error_text());
    return;
}

// Options for signing are specified in JSON.
let json = chilkat::JsonObject::new();

// In most cases, the signingCertificateV2 and signingTime attributes are required.
let _ = json.update_int("signingCertificateV2", 1);
let _ = json.update_int("signingTime", 1);

// Put the signature on page 1, top left
let _ = json.update_int("page", 1);
let _ = json.update_string("appearance.y", "top");
let _ = json.update_string("appearance.x", "left");

// Use a font scale of 10.0
let _ = json.update_string("appearance.fontScale", "10.0");

// In this example, the appearance of the digital signature will contain three lines:
// 1) The signing certificate's common name
// 2) The current date/time
// 3) Some arbitrary text.
// The keyword "cert_cn" is replaced with the Certificate's Subject Common Name.
// The keyword "current_dt" is replaced with the current date/time.
// Any number of appearance text lines can be added.
let _ = json.update_string("appearance.text[0]", "Digitally signed by: cert_cn");
let _ = json.update_string("appearance.text[1]", "current_dt");
let _ = json.update_string("appearance.text[2]", "The crazy brown fox jumps over the lazy dog.");

// Use a certificate on a smartcard or USB token.
let cert = chilkat::Cert::new();

// Provide the smartcard PIN.
// Set the smartcard PIN prior to calling LoadFromSmartcard.
// If the PIN is not explicitly provided here, the Windows OS should
// display a dialog for the PIN.
cert.set_smart_card_pin("123456");

// Load the certificate on the smartcard currently in the reader (or on the USB token).
// Pass an empty string to allow Chilkat to automatically choose the CSP (Cryptographi Service Provider).
// See Load Certificate on Smartcard for information about explicitly selecting a particular CSP.
if cert.load_from_smartcard("").is_err() {
    println!("{}", cert.last_error_text());
    return;
}

// Tell the pdf object to use the certificate for signing.
if pdf.set_signing_cert(&cert).is_err() {
    println!("{}", pdf.last_error_text());
    return;
}

if pdf.sign_pdf(&json, "qa_output/hello_signed_hsm.pdf").is_err() {
    println!("{}", pdf.last_error_text());
    return;
}

println!("The PDF has been successfully cryptographically signed using an HSM.");