Sample code for 30+ languages & platforms
Zig

Create Egypt ITIDA CAdES-BES .p7s Signature (File to File)

See more Egypt ITIDA Examples

Demonstrates how to create a .p7s signature that fits Egypt's ITIDA requirements.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    // There are many ways to load the certificate.
    // This example was created for a customer using an ePass2003 USB token.
    // Assuming the USB token is the only source of a hardware-based private key..
    cert.loadFromSmartcard("") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Tell the crypt component to use this cert.
    crypt.setSigningCert(cert) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    const cms_options = try chilkat.JsonObject.init();
    defer cms_options.deinit();
    cms_options.updateBool("DigestData", true) catch {};
    cms_options.updateBool("OmitAlgorithmIdNull", true) catch {};
    crypt.setCmsOptions(try cms_options.emit(alloc));

    // The CadesEnabled property applies to all methods that create CMS/PKCS7 signatures.
    // To create a CAdES-BES signature, set this property equal to true.
    crypt.setCadesEnabled(true);

    crypt.setHashAlgorithm("sha256");

    const json_signing_attrs = try chilkat.JsonObject.init();
    defer json_signing_attrs.deinit();
    json_signing_attrs.updateInt("contentType", 1) catch {};
    json_signing_attrs.updateInt("signingTime", 1) catch {};
    json_signing_attrs.updateInt("messageDigest", 1) catch {};
    json_signing_attrs.updateInt("signingCertificateV2", 1) catch {};
    crypt.setSigningAttributes(try json_signing_attrs.emit(alloc));

    // By default, all the certs in the chain of authentication are included in the signature.
    // If desired, we can choose to only include the signing certificate:
    crypt.setIncludeCertChain(false);

    // Make sure we sign the utf-8 byte representation of the JSON string
    crypt.setCharset("utf-8");

    // Create the CAdES-BES signature, which does not contain the data being signed.
    const path_of_file_to_sign = "someDir/someFile";
    const output_path = "outDir/someFile.p7s";
    crypt.createP7S(path_of_file_to_sign, output_path) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success!\n", .{});
}