Sample code for 30+ languages & platforms
React Native

FatturaPA XML Invoice Sign+Encrypt to P7M

See more Digital Signatures Examples

Demonstrates how to create a CAdES BES signed + encrypted invoice.xml.p7m for the Italian FatturaPA exchange system.

Chilkat React Native Downloads

React Native
import { Cert, Crypt2, JsonObject } from '@chilkat/react-native'

async function chilkatExample() {
  // This requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const crypt = new Crypt2();

  // Use a digital certificate and private key from a PFX file (.pfx or .p12).
  const pfxPath = 'qa_data/pfx/cert_test123.pfx';
  const pfxPassword = 'test123';

  const cert = new Cert();
  try {
    cert.loadPfxFile(pfxPath, pfxPassword);
  } catch {
    console.log(cert.lastErrorText);
    return;
  }

  // Provide the signing cert (with associated private key).
  try {
    crypt.setSigningCert(cert);
  } catch {
    console.log(crypt.lastErrorText);
    return;
  }

  // Indicate that SHA-256 should be used.
  crypt.hashAlgorithm = 'sha256';

  // Specify the signed attributes to be included.
  // (This is what makes it CAdES-BES compliant.)
  const jsonSignedAttrs = new JsonObject();
  jsonSignedAttrs.updateInt('contentType', 1);
  jsonSignedAttrs.updateInt('signingTime', 1);
  jsonSignedAttrs.updateInt('messageDigest', 1);
  jsonSignedAttrs.updateInt('signingCertificateV2', 1);
  crypt.signingAttributes = jsonSignedAttrs.emit();

  const inFile = 'qa_data/xml/IT01234567890_11002.xml';
  const sigFile = 'qa_data/fatturapa/signed.p7m';

  // Create the CAdES-BES signature, which contains the original data.
  try {
    await crypt.createP7MAsync(inFile, sigFile);
  } catch {
    console.log(crypt.lastErrorText);
    return;
  }

  // Now we'll encrypt what was signed using FatturaPA's certificate (from a PEM file)
  const encryptCert = new Cert();
  try {
    encryptCert.loadFromFile('qa_data/certs/fatturapa_cert.pem');
  } catch {
    console.log(encryptCert.lastErrorText);
    return;
  }

  crypt.cryptAlgorithm = 'pki';

  try {
    crypt.setEncryptCert(encryptCert);
  } catch {
    console.log(crypt.lastErrorText);
    return;
  }

  // Indicate the underlying bulk encryption algorithm to be used:
  crypt.pkcs7CryptAlg = 'aes';
  crypt.keyLength = 128;

  // There's one last option that could be set.  If is the RSA encryption encryption/padding scheme. 
  // By default, RSAES_PKCS1-V1_5 is used.  If desired, the OaepPadding property could be set to true to
  // use RSAES_OAEP.  (We'll leave it set at the default value of false)
  crypt.oaepPadding = false;

  // Everything is specified.  Encrypt the .p7m to create a new .p7m (which adds a layer of encryption around the opaque signature).
  // The output is PKCS7 in binary DER format.
  try {
    await crypt.ckEncryptFileAsync(sigFile, 'qa_output/signed_and_encrypted.p7m');
  } catch {
    console.log(crypt.lastErrorText);
    return;
  }

  console.log('Success.');
}