Sample code for 30+ languages & platforms
Perl

Add EncapsulatedTimestamp to Already-Signed XML

See more XML Digital Signatures Examples

Demonstrates how to add an EncapsulatedTimestamp to an existing XML signature.

Note: This example requires Chilkat v9.5.0.90 or greater.

Chilkat Perl Downloads

Perl
use chilkat();

$success = 0;

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Note: We cannot load the already-signed XML into a Chilkat XML object because it would re-format the XML when re-emitted.
# (i.e. indentation and whitespace could change, and it would invalidate the existing signature.)
# We must use a StringBuilder.
$sbXml = chilkat::CkStringBuilder->new();
$success = $sbXml->LoadFile("qa_data/xml_dsig_valid_samples/encapsulatedTimestamp_not_yet_added.xml","utf-8");
if ($success == 0) {
    print "Failed to load the XML file." . "\r\n";
    exit;
}

$dsig = chilkat::CkXmlDSig->new();
$success = $dsig->LoadSignatureSb($sbXml);
if ($success == 0) {
    print $dsig->lastErrorText() . "\r\n";
    exit;
}

if ($dsig->HasEncapsulatedTimeStamp() == 1) {
    print "This signed XML already has an EncapsulatedTimeStamp" . "\r\n";
    exit;
}

# Specify the timestamping authority URL
$json = chilkat::CkJsonObject->new();
$json->UpdateString("timestampToken.tsaUrl","http://timestamp.digicert.com");
$json->UpdateBool("timestampToken.requestTsaCert",1);

# Call AddEncapsulatedTimeStamp to add the EncapsulatedTimeStamp to the signature.
# Note: If the signed XML contains multiple signatures, the signature modified is the one 
# indicated by the dsig.Selector property.
$sbOut = chilkat::CkStringBuilder->new();
$success = $dsig->AddEncapsulatedTimeStamp($json,$sbOut);
if ($success == 0) {
    print $dsig->lastErrorText() . "\r\n";
    exit;
}

$sbOut->WriteFile("qa_output/addedEncapsulatedTimeStamp.xml","utf-8",0);

# The EncapsulatedTimeStamp can be validated when validating the signature by adding the VerifyEncapsulatedTimeStamp
# keyword to UncommonOptions.  See here:

# ----------------------------------------
# Verify the signatures we just produced...
$verifier = chilkat::CkXmlDSig->new();
$success = $verifier->LoadSignatureSb($sbOut);
if ($success != 1) {
    print $verifier->lastErrorText() . "\r\n";
    exit;
}

# Add "VerifyEncapsulatedTimeStamp" to the UncommonOptions to also verify any EncapsulatedTimeStamps
$verifier->put_UncommonOptions("VerifyEncapsulatedTimeStamp");

$numSigs = $verifier->get_NumSignatures();
$verifyIdx = 0;
while ($verifyIdx < $numSigs) {
    $verifier->put_Selector($verifyIdx);
    $verified = $verifier->VerifySignature(1);
    if ($verified != 1) {
        print $verifier->lastErrorText() . "\r\n";
        exit;
    }

    $verifyIdx = $verifyIdx + 1;
}

print "All signatures were successfully verified." . "\r\n";