Sample code for 30+ languages & platforms
Dart

EuroCert Cloud Sign XML

See more Signing in the Cloud Examples

Demonstrates how to sign XML using the EuroCert cloud provider. The signing of the hash happens on a hardware token on the EuroCert server. Everything else involving the updating the XML to add the signature happens locally within Chilkat.

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

  final pkcs11 = CkPkcs11();

  // Provide the path to the EuroCert Cloud PKCS11 driver.
  // If your application runs as a 64-bit process, use the path to the 64-bit ECSPKCS11.dll
  pkcs11.sharedLibPath = 'C:\\Users\\Public\\ECSIGNER\\PKCS11\\32\\ECSPKCS11.dll';

  // At this time, we don't know what should be used for the PIN.
  // Perhaps it is documented online by EuroCert?
  final pin = 'user:password';
  final userType = 1;

  try {
    pkcs11.quickSession(userType, pin);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  final cert = CkCert();
  try {
    cert.loadFromFile('qa_data/certs/myCert.cer');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Tell the certificate to link with the PKCS11 session.
  // The cert's private key should be installed on the CloudHSM.
  // If there are multiple private keys on the CloudHSM, then Chilkat will automatically
  // locate and use the private key corresponding to the certificate.
  try {
    cert.linkPkcs11(pkcs11);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // --------------------------------------------------------------------------
  // At this point, we have the cert to be used for signing.
  // Our XML signing code is the same as for a cert obtained from any other source..

  // First generate the following XML to be signed:
  // Use this online tool to generate code from sample XML: 
  // Generate Code to Create XML

  // <?xml version="1.0" encoding="UTF-8" standalone="no" ?>
  // <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
  //     <SOAP-ENV:Header>
  //         <wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" SOAP-ENV:mustUnderstand="1"></wsse:Security>
  //     </SOAP-ENV:Header>
  //     <SOAP-ENV:Body xmlns:SOAP-SEC="http://schemas.xmlsoap.org/soap/security/2000-12" SOAP-SEC:id="Body">
  //         <z:FooBar xmlns:z="http://example.com" />
  //     </SOAP-ENV:Body>
  // </SOAP-ENV:Envelope>

  final xml = CkXml();
  xml.tag = 'SOAP-ENV:Envelope';
  xml.addAttribute('xmlns:SOAP-ENV', 'http://schemas.xmlsoap.org/soap/envelope/');
  xml.updateAttrAt('SOAP-ENV:Header|wsse:Security', true, 'xmlns:wsse', 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd');
  xml.updateAttrAt('SOAP-ENV:Header|wsse:Security', true, 'SOAP-ENV:mustUnderstand', '1');
  xml.updateAttrAt('SOAP-ENV:Body', true, 'xmlns:SOAP-SEC', 'http://schemas.xmlsoap.org/soap/security/2000-12');
  xml.updateAttrAt('SOAP-ENV:Body', true, 'SOAP-SEC:id', 'Body');
  xml.updateAttrAt('SOAP-ENV:Body|z:FooBar', true, 'xmlns:z', 'http://example.com');

  final gen = CkXmlDSigGen();

  // Indicate where the Signature will be inserted.
  gen.sigLocation = 'SOAP-ENV:Envelope|SOAP-ENV:Header|wsse:Security';

  // Add a reference to the fragment of the XML to be signed.

  // Note: "Body" refers to the XML element having an "id" equal to "Body", where "id" is case insensitive
  // and where any namespace might qualify the attribute.  In this case, the SOAP-ENV:Body fragment is signed
  // NOT because the tag = "Body", but because it has SOAP-SEC:id="Body"
  gen.addSameDocRef('Body', 'sha1', 'EXCL_C14N', '', '');

  // (You can read about the SignedInfoPrefixList in the online reference documentation.  It's optional..)
  gen.signedInfoPrefixList = 'wsse SOAP-ENV';

  // Provide the private key for signing via the certificate, and indicate that
  // we want the base64 of the certificate embedded in the KeyInfo.
  gen.keyInfoType = 'X509Data';
  gen.x509Type = 'Certificate';

  final bUsePrivateKey = true;
  try {
    gen.setX509Cert(cert, bUsePrivateKey);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    pkcs11.closeSession();
    return;
  }

  // Everything's specified.  Now create and insert the Signature
  final sbXml = CkStringBuilder();
  xml.emitCompact = true;
  xml.getXmlSb(sbXml);

  try {
    gen.createXmlDSigSb(sbXml);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    pkcs11.closeSession();
    return;
  }

  // Examine the XML with the digital signature inserted
  print(sbXml.getAsString());

  // --------------------------------------------------------------------------

  // Revert to an unauthenticated session by calling Logout.
  try {
    pkcs11.logout();
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    pkcs11.closeSession();
    return;
  }

  // When finished, close the session.
  // It is important to close the session (memory leaks will occur if the session is not properly closed).
  try {
    pkcs11.closeSession();
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('Success.');
}