Sample code for 30+ languages & platforms
Xbase++

Create ICP-Brasil Compliant CMS Signature

See more CAdES Examples

Demonstrates how to create a .p7s signature that contains a data file, which in this case is a PDF. The .p7s will be compliant with the ICP-Brazil Digital Signature Standard.

The .p7s file created by this example can be verified at ICP-Brasil Online Verifier

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL cInFile
LOCAL oBd
LOCAL oCert
LOCAL oJsonSigningAttrs

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  ------------------------------------------------------------------------------------------------------
//  Note: This example creates a CMS signature (.p7s) that contains the PDF.
//  It is different than signing a PDF.  To sign a PDF where the resulting PDF contains the CMS signature,
//  see this example:  Sign PDF for ICP-Brasil
//  ------------------------------------------------------------------------------------------------------
oCrypt := CreateObject("Chilkat.Crypt2")

//  Any type of file can be signed.  It doesn't have to be a PDF.
cInFile := "qa_data/pdf/helloWorld.pdf"

oBd := CreateObject("Chilkat.BinData")
nSuccess := oBd:LoadFile(cInFile)
IF (nSuccess == 0)
    ? "Failed to load " + cInFile
    oCrypt:destroy()
    oBd:destroy()
    RETURN
ENDIF

//  We'll be using a certificate w/ private key stored on a smartcard for signing.
oCert := CreateObject("Chilkat.Cert")

//  If the smartcard or token requires a PIN, we can set it here to avoid the dialog...
oCert:SmartCardPin := "000000"

nSuccess := oCert:LoadFromSmartcard("")
IF (nSuccess != 1)
    ? oCert:LastErrorText
    oCrypt:destroy()
    oBd:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Tell the crypt component to use this cert.
nSuccess := oCrypt:SetSigningCert(oCert)
IF (nSuccess != 1)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    oBd:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Set properties for signing...
oCrypt:HashAlgorithm := "sha256"

oJsonSigningAttrs := CreateObject("Chilkat.JsonObject")
oJsonSigningAttrs:UpdateInt("contentType", 1)
oJsonSigningAttrs:UpdateInt("signingTime", 1)
oJsonSigningAttrs:UpdateInt("messageDigest", 1)
oJsonSigningAttrs:UpdateBool("signingCertificateV2", 1)

//  Listed here are the currently existing profiles. (Chilkat will add additional ICP Brasil policy profiles in future versions as new ones are created.)
//  See https://www.gov.br/iti/pt-br/assuntos/repositorio/artefatos-de-assinatura-digital for more information.
//  
//  PA_AD_RA --> 2.16.76.1.7.1.5.1
//  PA_AD_RA_v1_1 --> 2.16.76.1.7.1.5.1.1
//  PA_AD_RA_v1_2 --> 2.16.76.1.7.1.5.1.2
//  PA_AD_RA_v2_0 --> 2.16.76.1.7.1.5.2
//  PA_AD_RA_v2_1 --> 2.16.76.1.7.1.5.2.1
//  PA_AD_RA_v2_2 --> 2.16.76.1.7.1.5.2.2
//  PA_AD_RA_v2_3 --> 2.16.76.1.7.1.5.2.3
//  PA_AD_RA_v2_4 --> 2.16.76.1.7.1.5.2.4
//  PA_AD_RB --> 2.16.76.1.7.1.1.1
//  PA_AD_RB_v1_1 --> 2.16.76.1.7.1.1.1.1
//  PA_AD_RB_v2_0 --> 2.16.76.1.7.1.1.2
//  PA_AD_RB_v2_1 --> 2.16.76.1.7.1.1.2.1
//  PA_AD_RB_v2_2 --> 2.16.76.1.7.1.1.2.2
//  PA_AD_RB_v2_3 --> 2.16.76.1.7.1.1.2.3
//  PA_AD_RC --> 2.16.76.1.7.1.4.1
//  PA_AD_RC_v1_1 --> 2.16.76.1.7.1.4.1.1
//  PA_AD_RC_v2_0 --> 2.16.76.1.7.1.4.2
//  PA_AD_RC_v2_1 --> 2.16.76.1.7.1.4.2.1
//  PA_AD_RC_v2_2 --> 2.16.76.1.7.1.4.2.2
//  PA_AD_RC_v2_3 --> 2.16.76.1.7.1.4.2.3
//  PA_AD_RT --> 2.16.76.1.7.1.2.1
//  PA_AD_RT_v1_1 --> 2.16.76.1.7.1.2.1.1
//  PA_AD_RT_v2_0 --> 2.16.76.1.7.1.2.2
//  PA_AD_RT_v2_1 --> 2.16.76.1.7.1.2.2.1
//  PA_AD_RT_v2_2 --> 2.16.76.1.7.1.2.2.2
//  PA_AD_RT_v2_3 --> 2.16.76.1.7.1.2.2.3
//  PA_AD_RV --> 2.16.76.1.7.1.3.1
//  PA_AD_RV_v1_1 --> 2.16.76.1.7.1.3.1.1
//  PA_AD_RV_v2_0 --> 2.16.76.1.7.1.3.2
//  PA_AD_RV_v2_1 --> 2.16.76.1.7.1.3.2.1
//  PA_AD_RV_v2_2 --> 2.16.76.1.7.1.3.2.2
//  PA_AD_RV_v2_3 --> 2.16.76.1.7.1.3.2.3

//  Set the policy OID and the profile name
oJsonSigningAttrs:UpdateString("policyId.id", "2.16.76.1.7.1.1.2.3")
oJsonSigningAttrs:UpdateString("policyId.profile", "PA_AD_RB_v2_3")

oCrypt:SigningAttributes := oJsonSigningAttrs:Emit()

//  The Brazil government validator requires the ASN.1 data to be in "constructed octets" form..
oCrypt:UncommonOptions := "UseConstructedOctets,OmitAlgorithmIdNull"
oCrypt:IncludeCertChain := 0

//  Sign. 
nSuccess := oCrypt:OpaqueSignBd(oBd)
IF (nSuccess == 0)
    ? oCrypt:LastErrorText
    oCrypt:destroy()
    oBd:destroy()
    oCert:destroy()
    oJsonSigningAttrs:destroy()
    RETURN
ENDIF

//  Save to a .p7s
nSuccess := oBd:WriteFile("qa_output/helloWorld.pdf.p7s")

? "Success"

oCrypt:destroy()
oBd:destroy()
oCert:destroy()
oJsonSigningAttrs:destroy()