Sample code for 30+ languages & platforms
Tcl

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

set crypt [new_CkCrypt2]

# Create the hash to be signed...
CkCrypt2_put_HashAlgorithm $crypt "sha256"
CkCrypt2_put_EncodingMode $crypt "base64"
CkCrypt2_put_Charset $crypt "utf-8"
# Create the SHA256 hash of a string using the utf-8 byte representation.
# Return the hash as base64.
set base64Hash [CkCrypt2_hashStringENC $crypt "This is the string to be hashed"]

# Load a certificate for signing.
set cert [new_CkCert]

set success [CkCert_LoadPfxFile $cert "qa_data/pfx/cert_test123.pfx" "test123"]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCrypt2 $crypt
    delete_CkCert $cert
    exit
}

CkCrypt2_SetSigningCert $crypt $cert

# Sign the hash to create a base64 CMS signature (which does not contain the original data).
# We can get the signature in a single line of base64 by specifying "base64", or 
# we can get multi-line base64 by specifying "base64_mime".
CkCrypt2_put_EncodingMode $crypt "base64_mime"
set base64CmsSig [CkCrypt2_signHashENC $crypt $base64Hash "sha256" "base64"]
if {[CkCrypt2_get_LastMethodSuccess $crypt] == 0} then {
    puts [CkCrypt2_lastErrorText $crypt]
    delete_CkCrypt2 $crypt
    delete_CkCert $cert
    exit
}

# Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
# However, the encoding of the passed-in hash is indicated by the 3rd argument.

puts "CMS Signature: $base64CmsSig"

delete_CkCrypt2 $crypt
delete_CkCert $cert