Sample code for 30+ languages & platforms
Lianja

Add EncapsulatedTimestamp to Already-Signed XML

See more XML Digital Signatures Examples

Demonstrates how to add an EncapsulatedTimestamp to an existing XML signature.

Note: This example requires Chilkat v9.5.0.90 or greater.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Note: We cannot load the already-signed XML into a Chilkat XML object because it would re-format the XML when re-emitted.
// (i.e. indentation and whitespace could change, and it would invalidate the existing signature.)
// We must use a StringBuilder.
loSbXml = createobject("CkStringBuilder")
llSuccess = loSbXml.LoadFile("qa_data/xml_dsig_valid_samples/encapsulatedTimestamp_not_yet_added.xml","utf-8")
if (llSuccess = .F.) then
    ? "Failed to load the XML file."
    release loSbXml
    return
endif

loDsig = createobject("CkXmlDSig")
llSuccess = loDsig.LoadSignatureSb(loSbXml)
if (llSuccess = .F.) then
    ? loDsig.LastErrorText
    release loSbXml
    release loDsig
    return
endif

if (loDsig.HasEncapsulatedTimeStamp() = .T.) then
    ? "This signed XML already has an EncapsulatedTimeStamp"
    release loSbXml
    release loDsig
    return
endif

// Specify the timestamping authority URL
loJson = createobject("CkJsonObject")
loJson.UpdateString("timestampToken.tsaUrl","http://timestamp.digicert.com")
loJson.UpdateBool("timestampToken.requestTsaCert",.T.)

// Call AddEncapsulatedTimeStamp to add the EncapsulatedTimeStamp to the signature.
// Note: If the signed XML contains multiple signatures, the signature modified is the one 
// indicated by the dsig.Selector property.
loSbOut = createobject("CkStringBuilder")
llSuccess = loDsig.AddEncapsulatedTimeStamp(loJson,loSbOut)
if (llSuccess = .F.) then
    ? loDsig.LastErrorText
    release loSbXml
    release loDsig
    release loJson
    release loSbOut
    return
endif

loSbOut.WriteFile("qa_output/addedEncapsulatedTimeStamp.xml","utf-8",.F.)

// The EncapsulatedTimeStamp can be validated when validating the signature by adding the VerifyEncapsulatedTimeStamp
// keyword to UncommonOptions.  See here:

// ----------------------------------------
// Verify the signatures we just produced...
loVerifier = createobject("CkXmlDSig")
llSuccess = loVerifier.LoadSignatureSb(loSbOut)
if (llSuccess <> .T.) then
    ? loVerifier.LastErrorText
    release loSbXml
    release loDsig
    release loJson
    release loSbOut
    release loVerifier
    return
endif

// Add "VerifyEncapsulatedTimeStamp" to the UncommonOptions to also verify any EncapsulatedTimeStamps
loVerifier.UncommonOptions = "VerifyEncapsulatedTimeStamp"

lnNumSigs = loVerifier.NumSignatures
lnVerifyIdx = 0
do while lnVerifyIdx < lnNumSigs
    loVerifier.Selector = lnVerifyIdx
    llVerified = loVerifier.VerifySignature(.T.)
    if (llVerified <> .T.) then
        ? loVerifier.LastErrorText
        release loSbXml
        release loDsig
        release loJson
        release loSbOut
        release loVerifier
        return
    endif

    lnVerifyIdx = lnVerifyIdx + 1
enddo
? "All signatures were successfully verified."


release loSbXml
release loDsig
release loJson
release loSbOut
release loVerifier