Sample code for 30+ languages & platforms
Xbase++

CMS Sign Hash

Demonstrates how to use the SignHashENC method to sign a pre-computed hash. This method creates a CMS signature (PKCS7 detached signature).

This example requires Chilkat v9.5.0.90 or later.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL cBase64Hash
LOCAL oCert
LOCAL cBase64CmsSig

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oCrypt := CreateObject("Chilkat.Crypt2")

//  Create the hash to be signed...
oCrypt:HashAlgorithm := "sha256"
oCrypt:EncodingMode := "base64"
oCrypt:Charset := "utf-8"
//  Create the SHA256 hash of a string using the utf-8 byte representation.
//  Return the hash as base64.
cBase64Hash := oCrypt:HashStringENC("This is the string to be hashed")

//  Load a certificate for signing.
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadPfxFile("qa_data/pfx/cert_test123.pfx", "test123")
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oCrypt:destroy()
    oCert:destroy()
    RETURN
ENDIF

oCrypt:SetSigningCert(oCert)

//  Sign the hash to create a base64 CMS signature (which does not contain the original data).
//  We can get the signature in a single line of base64 by specifying "base64", or 
//  we can get multi-line base64 by specifying "base64_mime".
oCrypt:EncodingMode := "base64_mime"
cBase64CmsSig := oCrypt:SignHashENC(cBase64Hash, "sha256", "base64")
IF (oCrypt:LastMethodSuccess == 0)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Note: In the above call to SignHashENC, the encoding of the returned CMS signature is specified by the EncodingMode property.
//  However, the encoding of the passed-in hash is indicated by the 3rd argument.

? "CMS Signature: " + cBase64CmsSig

oCrypt:destroy()
oCert:destroy()