Chilkat HOME .NET Core C# Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi ActiveX Delphi DLL Go Java Lianja Mono C# Node.js Objective-C PHP ActiveX PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift 2 Swift 3,4,5... Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Delphi DLL) Verify XML Digital Signature with an RSA KeyThis example demonstrates how to verify an XML signature, where the RSA public key is embedded in the KeyInfo part of the Signature. When this is the case, nothing external is needed to verify the signature. This example requires Chilkat v9.5.0.69 or greater.
uses Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics, Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Http, StringBuilder, XmlDSig; ... procedure TForm1.Button1Click(Sender: TObject); var url: PWideChar; http: HCkHttp; sbXml: HCkStringBuilder; success: Boolean; dsig: HCkXmlDSig; i: Integer; bVerifyReferenceDigests: Boolean; bVerified: Boolean; begin // This example requires the Chilkat API to have been previously unlocked. // See Global Unlock Sample for sample code. // The signed XML to be verified in this example contains the following: // <?xml version="1.0" encoding="UTF-8"?> // <Signature xmlns="http://www.w3.org/2000/09/xmldsig#"> // <SignedInfo> // <CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315" /> // <SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /> // <Reference URI="#object"> // <DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /> // <DigestValue>OPnpF/ZNLDxJ/I+1F3iHhlmSwgo=</DigestValue> // </Reference> // </SignedInfo> // <SignatureValue>nihUFQg4mDhLgecvhIcKb9Gz8VRTOlw+adiZOBBXgK4JodEe5aFfCqm8WcRIT8GLLXSk8PsUP4//SsKqUBQkpotcAqQAhtz2v9kCWdoUDnAOtFZkd/CnsZ1sge0ndha40wWDV+nOWyJxkYgicvB8POYtSmldLLepPGMz+J7/Uws=</SignatureValue> // <KeyInfo> // <KeyValue> // <RSAKeyValue><Modulus>4IlzOY3Y9fXoh3Y5f06wBbtTg94Pt6vcfcd1KQ0FLm0S36aGJtTSb6pYKfyX7PqCUQ8wgL6xUJ5GRPEsu9gyz8ZobwfZsGCsvu40CWoT9fcFBZPfXro1Vtlh/xl/yYHm+Gzqh0Bw76xtLHSfLfpVOrmZdwKmSFKMTvNXOFd0V18=</Modulus><Exponent>AQAB</Exponent></RSAKeyValue> // </KeyValue> // </KeyInfo> // <Object Id="object">some text // with spaces and CR-LF.</Object> // </Signature> // The above XML is available at https://www.chilkatsoft.com/exampleData/signedSample1.xml // Fetch the XML and then verify it.. url := 'https://www.chilkatsoft.com/exampleData/signedSample1.xml'; http := CkHttp_Create(); sbXml := CkStringBuilder_Create(); success := CkHttp_QuickGetSb(http,url,sbXml); if (success <> True) then begin Memo1.Lines.Add(CkHttp__lastErrorText(http)); Exit; end; dsig := CkXmlDSig_Create(); // First load the XML containing the signatures to be verified. // Note that this particular Signature already contains the RSA public key that will be used // for verification. success := CkXmlDSig_LoadSignatureSb(dsig,sbXml); if (success <> True) then begin Memo1.Lines.Add(CkXmlDSig__lastErrorText(dsig)); Exit; end; // The XML in this example contains only 1 signature. // It's possible that an XML document can contain multiple signatures. // Each can be verified as follows: i := 0; while i < CkXmlDSig_getNumSignatures(dsig) do begin // Select the Nth signature by setting the Selector property. CkXmlDSig_putSelector(dsig,i); // The bVerifyReferenceDigests argument determines if we want // to also verify each reference digest. If set to False, // then only the SignedInfo part of the Signature is verified. bVerifyReferenceDigests := True; bVerified := CkXmlDSig_VerifySignature(dsig,bVerifyReferenceDigests); Memo1.Lines.Add('Signature ' + IntToStr(i + 1) + ' verified = ' + IntToStr(Ord(bVerified))); i := i + 1; end; CkHttp_Dispose(http); CkStringBuilder_Dispose(sbXml); CkXmlDSig_Dispose(dsig); end; |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.