Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Sign Mexico Pedimento

See more Misc Examples

Add a signature to a Mexico pedimento file.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // This is the contents before signing:

    // 500|1|3621|4199800|400||
    // 601|3621|4199800|400|IN|1||EKU9003173C9|EKU9003173C9FRNN09|1||
    // 507|4199800|IM|2006-7888">
    // 507|4199800|MS|2">
    // 800|4199800|1">
    // 801|M3621037.222|1|5|011|

    // This is the contents after signing

    // 500|1|3621|4199800|400||
    // 601|3621|4199800|400|IN|1||EKU9003173C9|EKU9003173C9FRNN09|1||
    // 507|4199800|IM|2006-7888">
    // 507|4199800|MS|2">
    // 800|4199800|1|fhP2Ker54D2+3+UZch23F0E72 .... 9qNSPIuAqpj524qLZbbA==|30001000000500003416|
    // 801|M3621037.222|1|5|011|

    // First create the text to be signed.
    const b_crlf = true;
    const sb = try chilkat.StringBuilder.init();
    defer sb.deinit();
    // Use CRLF line endings.
    sb.appendLine("500|1|3621|4199800|400||", b_crlf) catch {};
    sb.appendLine("601|3621|4199800|400|IN|1||EKU9003173C9|EKU9003173C9FRNN09|1||", b_crlf) catch {};
    sb.appendLine("507|4199800|IM|2006-7888">", b_crlf) catch {};
    sb.appendLine("507|4199800|MS|2">", b_crlf) catch {};

    // Generate the MD5 hash of what we have so far..
    const md5_base64 = try sb.getHash(alloc, "md5", "base64", "utf-8");
    std.debug.print("MD5 hash = {s}\n", .{md5_base64});

    // Complete the original file.
    // After signing, we'll update the BASE64_SIGNATURE and CERT_SERIAL
    sb.appendLine("800|4199800|1|BASE64_SIGNATURE|CERT_SERIAL|", b_crlf) catch {};
    sb.appendLine("801|M3621037.222|1|5|011|", b_crlf) catch {};

    // We're going to sign the MD5 hash using the private key.
    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    priv_key.loadAnyFormatFile("qa_data/certs/mexico_test/Certificados_de_Prueba/Certificados_Pruebas/Personas Morales/EKU9003173C9_20230517223532/CSD_EKU9003173C9_20230517223903/CSD_Sucursal_1_EKU9003173C9_20230517_223850.key", "12345678a") catch {
        std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
        return;
    };

    // Generate the ASN.1 to be signed.

    // <sequence>
    //     <sequence>
    //         <oid>1.2.840.113549.2.5</oid>
    //         <null/>
    //     </sequence>
    //     <octets>SwxHfaJhG+N3pPqay6UzVA==</octets>
    // </sequence>

    const xml = try chilkat.Xml.init();
    defer xml.deinit();
    xml.setTag("sequence");
    xml.updateChildContent("sequence|oid", "1.2.840.113549.2.5");
    xml.updateChildContent("sequence|null", "");
    xml.updateChildContent("octets", md5_base64);

    const asn = try chilkat.Asn.init();
    defer asn.deinit();
    asn.loadAsnXml(try xml.getXml(alloc)) catch {};
    std.debug.print("ASN.1 = {s}\n", .{try asn.getEncodedDer(alloc, "base64")});

    // Sign with the private key.
    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();
    rsa.usePrivateKey(priv_key) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // Create the opaque signature.
    const bd_sig = try chilkat.BinData.init();
    defer bd_sig.deinit();
    bd_sig.appendEncoded(try asn.getEncodedDer(alloc, "base64"), "base64") catch {};
    rsa.signRawBd(bd_sig) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // bd now contains the opaque signature, which embeds the ASN.1, which contains the MD5 hash.
    // We're going to add this line:
    // 800|4199800|1|BASE64_SIGNATURE|CERT_SERIAL_NUM|

    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadFromFile("qa_data/certs/mexico_test/Certificados_de_Prueba/Certificados_Pruebas/Personas Morales/EKU9003173C9_20230517223532/CSD_EKU9003173C9_20230517223903/CSD_Sucursal_1_EKU9003173C9_20230517_223850.cer") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    const serial_hex = try cert.getSerialNumber(alloc);
    // The serial in hex form looks like this:   3330303031303030303030353030303033343136
    // Decode to us-ascii.
    const sb_serial = try chilkat.StringBuilder.init();
    defer sb_serial.deinit();
    sb_serial.decodeAndAppend(serial_hex, "hex", "us-ascii") catch {};
    std.debug.print("serial number in us-ascii: {s}\n", .{try sb_serial.getAsString(alloc)});

    var num_replaced: i32 = sb.replace("CERT_SERIAL", try sb_serial.getAsString(alloc));
    num_replaced = sb.replace("BASE64_SIGNATURE", try bd_sig.getEncoded(alloc, "base64"));

    std.debug.print("------------------------------------\n", .{});
    std.debug.print("Result:\n", .{});
    std.debug.print("{s}\n", .{try sb.getAsString(alloc)});
}