Sample code for 30+ languages & platforms
Unicode C

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Unicode C Downloads

Unicode C
#include <C_CkCrypt2W.h>
#include <C_CkCertW.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkCrypt2W crypt;
    const wchar_t *base64Hash;
    HCkCertW cert;
    const wchar_t *base64CmsSig;

    success = FALSE;

    //  This example requires the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    crypt = CkCrypt2W_Create();

    //  Create the hash to be signed...
    CkCrypt2W_putHashAlgorithm(crypt,L"sha256");
    CkCrypt2W_putEncodingMode(crypt,L"base64");
    CkCrypt2W_putCharset(crypt,L"utf-8");
    //  Create the SHA256 hash of a string using the utf-8 byte representation.
    //  Return the hash as base64.
    base64Hash = CkCrypt2W_hashStringENC(crypt,L"This is the string to be hashed");

    //  Load a certificate for signing.
    cert = CkCertW_Create();
    success = CkCertW_LoadPfxFile(cert,L"qa_data/pfx/cert_test123.pfx",L"test123");
    if (success == FALSE) {
        wprintf(L"%s\n",CkCertW_lastErrorText(cert));
        CkCrypt2W_Dispose(crypt);
        CkCertW_Dispose(cert);
        return;
    }

    CkCrypt2W_SetSigningCert(crypt,cert);

    //  Sign the hash to create a base64 CMS signature (which does not contain the original data).
    //  We can get the signature in a single line of base64 by specifying "base64", or 
    //  we can get multi-line base64 by specifying "base64_mime".
    CkCrypt2W_putEncodingMode(crypt,L"base64_mime");
    base64CmsSig = CkCrypt2W_signHashENC(crypt,base64Hash,L"sha256",L"base64");
    if (CkCrypt2W_getLastMethodSuccess(crypt) == FALSE) {
        wprintf(L"%s\n",CkCrypt2W_lastErrorText(crypt));
        CkCrypt2W_Dispose(crypt);
        CkCertW_Dispose(cert);
        return;
    }

    //  Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
    //  However, the encoding of the passed-in hash is indicated by the 3rd argument.

    wprintf(L"CMS Signature: %s\n",base64CmsSig);


    CkCrypt2W_Dispose(crypt);
    CkCertW_Dispose(cert);

    }