Zig Requires Chilkat v11.0.0+
Zig
Create JPK VAT metadata XML
See more RSA Examples
Demonstrates how to create the JPK VAT metadata XML (InitUpload) that will be signed using XADES.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// First build an InitUpload XML template
// Use this online tool to generate the code from the sample XML below:
// Generate Code to Create XML
// <InitUpload xmlns="http://e-dokumenty.mf.gov.pl">
// <DocumentType>JPK</DocumentType>
// <Version>01.02.01.20160617</Version>
// <EncryptionKey algorithm="RSA" encoding="Base64" mode="ECB" padding="PKCS#1">F9EhKFec...uWqAWUIg==</EncryptionKey>
// <DocumentList>
// <Document>
// <FormCode schemaVersion="1-1" systemCode="JPK_VAT (3)">JPK_VAT</FormCode>
// <FileName>JPK_VAT_3_v1-1_20181201.xml</FileName>
// <ContentLength>8736</ContentLength>
// <HashValue algorithm="SHA-256" encoding="Base64">JFDI1pItwh6dj/Xe1uts/x61qnjZ4DLHpkZMhmf1oKQ=</HashValue>
// <FileSignatureList filesNumber="1">
// <Packaging>
// <SplitZip mode="zip" type="split"/>
// </Packaging>
// <Encryption>
// <AES block="16" mode="CBC" padding="PKCS#7" size="256">
// <IV bytes="16" encoding="Base64">z64oN9zXHt1+S3XACRSCYw==</IV>
// </AES>
// </Encryption>
// <FileSignature>
// <OrdinalNumber>1</OrdinalNumber>
// <FileName>JPK_VAT_3_v1-1_20181201-000.xml.zip.aes</FileName>
// <ContentLength>16</ContentLength>
// <HashValue algorithm="MD5" encoding="Base64">5NX0q1935fvMjLFV7E1yDw==</HashValue>
// </FileSignature>
// </FileSignatureList>
// </Document>
// </DocumentList>
// </InitUpload>
const xml = try chilkat.Xml.init();
defer xml.deinit();
xml.setTag("InitUpload");
xml.addAttribute("xmlns", "http://e-dokumenty.mf.gov.pl") catch {};
xml.updateChildContent("DocumentType", "JPK");
xml.updateChildContent("Version", "01.02.01.20160617");
xml.updateAttrAt("EncryptionKey", true, "algorithm", "RSA") catch {};
xml.updateAttrAt("EncryptionKey", true, "encoding", "Base64") catch {};
xml.updateAttrAt("EncryptionKey", true, "mode", "ECB") catch {};
xml.updateAttrAt("EncryptionKey", true, "padding", "PKCS#1") catch {};
xml.updateChildContent("EncryptionKey", "TO BE DETERMINED");
xml.updateAttrAt("DocumentList|Document|FormCode", true, "schemaVersion", "1-1") catch {};
xml.updateAttrAt("DocumentList|Document|FormCode", true, "systemCode", "JPK_VAT (3)") catch {};
xml.updateChildContent("DocumentList|Document|FormCode", "JPK_VAT");
xml.updateChildContent("DocumentList|Document|FileName", "JPK_VAT_3_v1-1_20181201.xml");
xml.updateChildContent("DocumentList|Document|ContentLength", "9999");
xml.updateAttrAt("DocumentList|Document|HashValue", true, "algorithm", "SHA-256") catch {};
xml.updateAttrAt("DocumentList|Document|HashValue", true, "encoding", "Base64") catch {};
xml.updateChildContent("DocumentList|Document|HashValue", "TO BE DETERMINED");
xml.updateAttrAt("DocumentList|Document|FileSignatureList", true, "filesNumber", "1") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "mode", "zip") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "type", "split") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "block", "16") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "mode", "CBC") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "padding", "PKCS#7") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "size", "256") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "bytes", "16") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "encoding", "Base64") catch {};
xml.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", "TO BE DETERMINED");
xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|OrdinalNumber", "1");
xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|FileName", "JPK_VAT_3_v1-1_20181201-000.xml.zip.aes");
xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", "9999");
xml.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "algorithm", "MD5") catch {};
xml.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "encoding", "Base64") catch {};
xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", "TO BE DETERMINED");
// ------------------------------------------------------------
// Step 1: Load our JPK_VAT XML and update the DocumentList|Document|HashValue
// and DocumentList|Document|ContentLength
const bd_xml = try chilkat.BinData.init();
defer bd_xml.deinit();
bd_xml.loadFile("qa_data/xml_dsig/jpk_vat/JPK_VAT_3_v1-1_20181201-000.xml") catch {
std.debug.print("Failed to load XML file.\n", .{});
return;
};
xml.updateChildContentInt("DocumentList|Document|ContentLength", bd_xml.getNumBytes());
const crypt = try chilkat.Crypt2.init();
defer crypt.deinit();
crypt.setHashAlgorithm("sha256");
crypt.setEncodingMode("base64");
xml.updateChildContent("DocumentList|Document|HashValue", try crypt.hashBdENC(alloc, bd_xml));
// ------------------------------------------------------------
// Step 2: Create a Zip archive containing the XML.
const zip = try chilkat.Zip.init();
defer zip.deinit();
// The filename we pass here doesn't matter because we won't actually be creating a .zip file.
zip.newZip("anything.zip") catch {};
zip.addBd("JPK_VAT_3_v1-1_20181201-000.xml", bd_xml) catch {};
// Write the .zip file to a BinData object.
const bd_zip = try chilkat.BinData.init();
defer bd_zip.deinit();
zip.writeBd(bd_zip) catch {};
// ------------------------------------------------------------
// Step 3: Generate a random 256-bit AES key (32-bytes)
const prng = try chilkat.Prng.init();
defer prng.deinit();
const bd_aes_key = try chilkat.BinData.init();
defer bd_aes_key.deinit();
prng.genRandomBd(32, bd_aes_key) catch {};
const iv_bytes = try prng.genRandom(alloc, 16, "base64");
// Store the IV (base64 string) in the XML.
xml.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", iv_bytes);
// ------------------------------------------------------------
// Step 4: AES encrypt our zip archive (the contents of bdZip)
crypt.setCipherMode("cbc");
crypt.setKeyLength(256);
crypt.setCryptAlgorithm("aes");
crypt.setPaddingScheme(0);
crypt.setEncodedIV(iv_bytes, "base64");
crypt.setEncodedKey(try bd_aes_key.getEncoded(alloc, "base64"), "base64");
// AES by definition has a block size of 16.
crypt.encryptBd(bd_zip) catch {};
// bdZip now contains the AES encrypted data.
// Note: This is NOT the same as a zip where the contents are AES encrypted.
// In that case, we have an unencrypted zip structure with AES encrypted files within.
// In our case, the entire zip file image is encrypted.
// Save the bdZip to a file. This is what will get sent to e-dokumenty.mf.gov.pl
try bd_zip.writeFile("qa_output/JPK_VAT_3_v1-1_20181201-000.xml.zip.aes");
xml.updateChildContentInt("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", bd_zip.getNumBytes());
// ------------------------------------------------------------
// Step 4: RSA Encrypt the AES key using the public key certificate provided by the Ministry of Finance
const cert = try chilkat.Cert.init();
defer cert.deinit();
cert.loadFromFile("qa_data/pem/mf_public_rsa.pem") catch {
std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
return;
};
const pub_key = try chilkat.PublicKey.init();
defer pub_key.deinit();
cert.getPublicKey(pub_key) catch {};
const rsa = try chilkat.Rsa.init();
defer rsa.deinit();
rsa.usePublicKey(pub_key) catch {};
rsa.setEncodingMode("base64");
rsa.setLittleEndian(false);
// in-place RSA encrypt the contents of bdAesKey.
rsa.encryptBd(bd_aes_key, false) catch {};
xml.updateChildContent("EncryptionKey", try bd_aes_key.getEncoded(alloc, "base64"));
// Step 5: We forgot to get the MD5 hash of the AES encrypted zip.
// (I'm assuming we need the MD5 of the encrypted zip as opposed to the MD5 of the pre-encrypted zip..)
crypt.setHashAlgorithm("md5");
xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", try crypt.hashBdENC(alloc, bd_zip));
// At this point, the XML is prepared and the AES encrypted image of the zip file is written
// to a file (and also in bdZip).
const final_xml = try xml.getXml(alloc);
std.debug.print("{s}\n", .{final_xml});
xml.saveXml("qa_output/jpk_vat.xml") catch {};
std.debug.print("Finished.\n", .{});
}