Lianja
Lianja
Verify an XML Signature with Multiple References
See more XML Digital Signatures Examples
Demonstrates how to verify an XML digital signature that contains multiple references.Chilkat Lianja Downloads
llSuccess = .F.
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// An example of an enveloping XML signature with mulitple references is available at
// https://www.chilkatsoft.com/exampleData/envelopedMultipleRefs.xml
// This example will show how to verify the signature and all references, and also how
// to verify each reference individually. This is useful to distinguish which part
// of the XML signature validation failed. It could be that one or more of the references
// failed because of a hash computation mismatch. Or it could be that the signature over
// the SignedInfo failed.
// First, let's grab the sample XML signature.
loHttp = createobject("CkHttp")
loSbXml = createobject("CkStringBuilder")
llSuccess = loHttp.QuickGetSb("https://www.chilkatsoft.com/exampleData/envelopedMultipleRefs.xml",loSbXml)
if (llSuccess <> .T.) then
? loHttp.LastErrorText
release loHttp
release loSbXml
return
endif
// Load the XML containing the signature to be verified.
loVerifier = createobject("CkXmlDSig")
llSuccess = loVerifier.LoadSignatureSb(loSbXml)
if (llSuccess <> .T.) then
? loVerifier.LastErrorText
release loHttp
release loSbXml
release loVerifier
return
endif
llVerifyReferenceDigests = .T.
// The quick way to validate all references and the signature over the SignedInfo
// is to call VerifySignature with verifyReferenceDigests equal to .T..
llVerified = loVerifier.VerifySignature(llVerifyReferenceDigests)
? "Signature and all reference digests verified = " + str(llVerified)
// Let's pretend the call to VerifySignature returned .F.. Something did not validate.
// Was it one or more of the References that did not hash to the correct value?
// Or was it the signature over the SignedInfo that failed?
// We can check just the signature over the SignedInfo by passing .F. to VerifySignature.
// This allows us to skip the hashing and checking each Reference.
llVerifyReferenceDigests = .F.
llSignedInfoVerified = loVerifier.VerifySignature(llVerifyReferenceDigests)
? "Neglecting the reference hashes, the SignedInfo validation result = " + str(llSignedInfoVerified)
// We can also verify each reference digest separately
lnNumRefs = loVerifier.NumReferences
i = 0
do while i < lnNumRefs
llRefDigestVerified = loVerifier.VerifyReferenceDigest(i)
? "Reference " + str(i) + " digest verified = " + str(llRefDigestVerified)
i = i + 1
enddo
// For this sample XML signature with 3 References, we get the following output:
// Signature and all reference digests verified = True
// Neglecting the reference hashes, the SignedInfo validation result = True
// Reference 0 digest verified = True
// Reference 1 digest verified = True
// Reference 2 digest verified = Tru
release loHttp
release loSbXml
release loVerifier