Sample code for 30+ languages & platforms
Lianja

Create XML Signature with External Data Reference

See more XML Digital Signatures Examples

Demonstrates how to create an XML digital signature where the data is external. In this case, the data is a JPG file.

This example requires Chilkat v9.5.0.69 or greater.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// This example inserts an XML signature in the following XML:

// <?xml version="1.0" encoding="UTF-8" standalone="no"?>
// <abc>
//   <xyz>
//     <jpg>
//         <name>starfish.jpg</name>
//         <url>https://www.chilkatsoft.com/images/starfish.jpg</url>
//     </jpg>
//   </xyz>
// </abc>

// The above XML is available at https://www.chilkatsoft.com/exampleData/addSignatureToThis.xml
// First fetch the XML:

lcUrl = "https://www.chilkatsoft.com/exampleData/addSignatureToThis.xml"
loHttp = createobject("CkHttp")
loSbXml = createobject("CkStringBuilder")
llSuccess = loHttp.QuickGetSb(lcUrl,loSbXml)
if (llSuccess <> .T.) then
    ? loHttp.LastErrorText
    release loHttp
    release loSbXml
    return
endif

// We'll use an RSA private key for signing.  
loRsaKey = createobject("CkPrivateKey")
llSuccess = loRsaKey.LoadPemFile("qa_data/rsa/rsaPrivKey_pkcs8.pem")
if (llSuccess <> .T.) then
    ? loRsaKey.LastErrorText
    release loHttp
    release loSbXml
    release loRsaKey
    return
endif

loXmlSigGen = createobject("CkXmlDSigGen")

// Indicate were the Signature will be inserted:
loXmlSigGen.SigLocation = "abc|xyz|jpg"

// Provide the RSA key to be used for signing:
loXmlSigGen.SetPrivateKey(loRsaKey)

// Fetch the JPG image data.
lcJpgUrl = "https://www.chilkatsoft.com/images/starfish.jpg"
loJpgData = createobject("CkBinData")
llSuccess = loHttp.QuickGetBd(lcJpgUrl,loJpgData)
if (llSuccess <> .T.) then
    ? loHttp.LastErrorText
    release loHttp
    release loSbXml
    release loRsaKey
    release loXmlSigGen
    release loJpgData
    return
endif

// Add the external data reference:
loXmlSigGen.AddExternalBinaryRef(lcJpgUrl,loJpgData,"sha256","")

// Create the XML digital signature:
llSuccess = loXmlSigGen.CreateXmlDSigSb(loSbXml)
if (llSuccess <> .T.) then
    ? loXmlSigGen.LastErrorText
    release loHttp
    release loSbXml
    release loRsaKey
    release loXmlSigGen
    release loJpgData
    return
endif

// Examine the XML that now contains the Signature:
? loSbXml.GetAsString()

// <?xml version="1.0" encoding="UTF-8" standalone="no"?>
// <abc>
//   <xyz>
//     <jpg>
//         <name>starfish.jpg</name>
//         <url>https://www.chilkatsoft.com/images/starfish.jpg</url>
//     <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference URI="https://www.chilkatsoft.com/images/starfish.jpg"><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>AOU810yJV5Np/DnO29qpObqiTSTTCDvxGsX5ayiTYXI=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>ApHRr6nilNrzt3dLveC9zlPoSllaCMfHsbAwr+vYBPkHkJ4wD5LzDDhi1tSJZAAeTckmvSqIG3Wi0rgXQiSM644MD3coBFx4QgrY+GZ+XJJE2Y0Ye3VvaQBiRdUW3INGsW4GLubncgQk5JhuAQjo6O/GKpfEuYqUJj/6CLHLQwMPwbZ2043ykgzuPFoOZf6EydJMBAn1ORMvrpUn+zuA9UngOTGap6eWE4CeiNx23BRC2wSztbUjdCLcqXvgiYu/v0tBNaTcwy7b6+IFtwv/lNUUBUQJ/3p+aErzFn3wLeH3yeqpDCU0U6Dqu5SS1jYupcWWsLHJjYnj2066DPJi/g==</ds:SignatureValue><ds:KeyInfo><ds:KeyValue><ds:RSAKeyValue><ds:Modulus>sXeRhM55P13FbpNcXAMR3olbw2Wa6keZIHu5YTZYUBTlYWId+pNiwUz3zFIEo+0IfYR0H27ybIycQO+1IIzJofUFNMAL3tZps2OKPlsjuCPls6kXpXhv/gvhux8LrCtp4PcKWqJ6QVOZKChc7WAx40qFWzHi57ueqRTv3x0kESqGg/VjsqyTEvb55psJO2RsfhLT7+YVh3hImRM3RDaJdkTkPuOxeFyT6N7VXD09329sLuS3QkUbE9zEKDnz9X3d8dEQdJhSI9ba5fxl8R7fu8pB67ElfzFml96X1jLFtzy1pzOT5Fc4ROcaqlYckVzdBq9sxezm6MYmDBjNAcibRw==</ds:Modulus><ds:Exponent>AQAB</ds:Exponent></ds:RSAKeyValue></ds:KeyValue></ds:KeyInfo></ds:Signature></jpg>
//   </xyz>
// </abc>
// 


release loHttp
release loSbXml
release loRsaKey
release loXmlSigGen
release loJpgData