Sample code for 30+ languages & platforms
PureBasic

Alliance Access LAU Sign Message (XML Signature using HMAC-SHA-256)

See more XML Digital Signatures Examples

Demonstrates how to sign XML according to the requirements for Alliance Access LAU (Local Authentication) using HMAC-SHA-256.

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkStringBuilder.pb"
IncludeFile "CkXml.pb"
IncludeFile "CkXmlDSigGen.pb"

Procedure ChilkatExample()

    success.i = 0

    ; This example requires the Chilkat API to have been previously unlocked.
    ; See Global Unlock Sample for sample code.

    ; We begin with this message:

    ; <?xml version="1.0" encoding="utf-8"?>
    ; <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
    ;   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
    ;     <Saa:Revision>2.0.7</Saa:Revision>
    ;     <Saa:Header>
    ;         <Saa:Message>
    ; 			<test>blah blah</test>
    ;         </Saa:Message>
    ;     </Saa:Header>
    ;     <Saa:Body>...</Saa:Body>
    ;     <Saa:LAU>
    ;     </Saa:LAU>
    ; </Saa:DataPDU>

    ; And we want so sign to create this as the result:
    ; The signed XML we'll create will not be indented and pretty-printed like this.
    ; Instead, we'll use the "CompactSignedXml" behavior to produce compact single-line XML.

    ; <?xml version="1.0" encoding="utf-8"?>
    ; <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
    ;   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
    ;     <Saa:Revision>2.0.7</Saa:Revision>
    ;     <Saa:Header>
    ;         <Saa:Message>
    ; 			<test>blah blah</test>
    ;         </Saa:Message>
    ;     </Saa:Header>
    ;     <Saa:Body>...</Saa:Body>
    ;     <Saa:LAU>
    ;         <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    ;             <ds:SignedInfo>
    ;                 <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    ;                 <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#hmac-sha256"/>
    ;                 <ds:Reference URI="">
    ;                     <ds:Transforms>
    ;                         <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
    ;                         <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    ;                     </ds:Transforms>
    ;                     <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    ;                     <ds:DigestValue>Y7oScHnYOUQvni/TSzZbDec+HR+mWIFH149GXpwj1Ws=</ds:DigestValue>
    ;                 </ds:Reference>
    ;             </ds:SignedInfo>
    ;             <ds:SignatureValue>6ynF/FcwbPsHrtlj3h2agJigdnvpbO6hOzKSRGzqkw0=</ds:SignatureValue>
    ;         </ds:Signature>
    ;     </Saa:LAU>
    ; </Saa:DataPDU>

    success = 1

    ; Create the XML to be signed...

    ; (The XML does not need to be created this way.  It can be loaded from a file or a string.)
    ; Also, use this online tool to generate code from sample XML: 
    ; Generate Code to Create XML

    xmlToSign.i = CkXml::ckCreate()
    If xmlToSign.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    CkXml::setCkTag(xmlToSign, "Saa:DataPDU")
    CkXml::ckAddAttribute(xmlToSign,"xmlns:Saa","urn:swift:saa:xsd:saa.2.0")
    CkXml::ckAddAttribute(xmlToSign,"xmlns:Sw","urn:swift:snl:ns.Sw")
    CkXml::ckAddAttribute(xmlToSign,"xmlns:SwGbl","urn:swift:snl:ns.SwGbl")
    CkXml::ckAddAttribute(xmlToSign,"xmlns:SwInt","urn:swift:snl:ns:SwInt")
    CkXml::ckAddAttribute(xmlToSign,"xmlns:SwSec","url:swift:snl:ns.SwSec")
    CkXml::ckUpdateChildContent(xmlToSign,"Saa:Revision","2.0.7")
    CkXml::ckUpdateChildContent(xmlToSign,"Saa:Header|Saa:Message|test","blah blah")
    CkXml::ckUpdateChildContent(xmlToSign,"Saa:Body","...")
    CkXml::ckUpdateChildContent(xmlToSign,"Saa:LAU","")

    gen.i = CkXmlDSigGen::ckCreate()
    If gen.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    CkXmlDSigGen::setCkSigLocation(gen, "Saa:DataPDU|Saa:LAU")
    CkXmlDSigGen::setCkSigLocationMod(gen, 0)
    CkXmlDSigGen::setCkSigNamespacePrefix(gen, "ds")
    CkXmlDSigGen::setCkSigNamespaceUri(gen, "http://www.w3.org/2000/09/xmldsig#")
    CkXmlDSigGen::setCkSignedInfoCanonAlg(gen, "EXCL_C14N")
    CkXmlDSigGen::setCkSignedInfoDigestMethod(gen, "sha256")

    ; You may alternatively choose "IndentedSignature" instead of "CompactSignedXml"
    CkXmlDSigGen::setCkBehaviors(gen, "CompactSignedXml")

    CkXmlDSigGen::ckAddSameDocRef(gen,"","sha256","EXCL_C14N","","")

    ; Specify the HMAC key.
    ; For example, if the HMAC key is to be the us-ascii bytes of the string "secret",
    ; the HMAC key can be set in any of the following ways (and also more ways not shown here..)
    CkXmlDSigGen::ckSetHmacKey(gen,"secret","ascii")
    ; or
    CkXmlDSigGen::ckSetHmacKey(gen,"c2VjcmV0","base64")
    ; or
    CkXmlDSigGen::ckSetHmacKey(gen,"736563726574","hex")

    ; Sign the XML..
    sbXml.i = CkStringBuilder::ckCreate()
    If sbXml.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    CkXml::ckGetXmlSb(xmlToSign,sbXml)
    success = CkXmlDSigGen::ckCreateXmlDSigSb(gen,sbXml)
    If success <> 1
        Debug CkXmlDSigGen::ckLastErrorText(gen)
        CkXml::ckDispose(xmlToSign)
        CkXmlDSigGen::ckDispose(gen)
        CkStringBuilder::ckDispose(sbXml)
        ProcedureReturn
    EndIf

    ; Save the signed XML to a file.
    success = CkStringBuilder::ckWriteFile(sbXml,"qa_output/signedXml.xml","utf-8",0)

    ; Show the signed XML.
    Debug CkStringBuilder::ckGetAsString(sbXml)


    CkXml::ckDispose(xmlToSign)
    CkXmlDSigGen::ckDispose(gen)
    CkStringBuilder::ckDispose(sbXml)


    ProcedureReturn
EndProcedure