Sample code for 30+ languages & platforms
Android™

Sign JSON (or any Text) to Create a Detached PKCS7 Signature

Demonstrates how to sign JSON or any string using a certificate + private key from a .p12/.pfx to create a detached PKCS7 signature. (A detached signature is one that does not embed the original signed data.)

Chilkat Android™ Downloads

Android™
// Important: Don't forget to include the call to System.loadLibrary
// as shown at the bottom of this code sample.
package com.test;

import android.app.Activity;
import com.chilkatsoft.*;

import android.widget.TextView;
import android.os.Bundle;

public class SimpleActivity extends Activity {

  private static final String TAG = "Chilkat";

  // Called when the activity is first created.
  @Override
  public void onCreate(Bundle savedInstanceState) {
    super.onCreate(savedInstanceState);

    boolean success = false;

    //  This example assumes the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    CkCrypt2 crypt = new CkCrypt2();

    CkCert cert = new CkCert();
    success = cert.LoadPfxFile("qa_data/pfx/cert_test123.pfx","test123");
    if (success != true) {
        Log.i(TAG, cert.lastErrorText());
        return;
        }

    //  Tell the crypt component to use this cert.
    success = crypt.SetSigningCert(cert);
    if (success != true) {
        Log.i(TAG, crypt.lastErrorText());
        return;
        }

    crypt.put_HashAlgorithm("sha256");

    //  By default, all the certs in the chain of authentication are included in the signature.
    //  If desired, we can choose to only include the signing certificate:
    crypt.put_IncludeCertChain(false);

    //  Create the detached signature, which does NOT contain the original data.
    //  To create a PKCS7 signature that contains the original data, see CAdES Sign JSON
    crypt.put_Charset("utf-8");
    CkByteData detachedSig = new CkByteData();
    String stringToSign = "{ \"abc\": 123}";
    success = crypt.SignString(stringToSign,detachedSig);
    if (crypt.get_LastMethodSuccess() == false) {
        Log.i(TAG, crypt.lastErrorText());
        return;
        }

    //  Verify the signature against the original data.
    boolean verified = crypt.VerifyString(stringToSign,detachedSig);
    if (verified == false) {
        Log.i(TAG, crypt.lastErrorText());
        return;
        }

    Log.i(TAG, "Success!");

  }

  static {
      System.loadLibrary("chilkat");

      // Note: If the incorrect library name is passed to System.loadLibrary,
      // then you will see the following error message at application startup:
      //"The application <your-application-name> has stopped unexpectedly. Please try again."
  }
}