Sample code for 30+ languages & platforms
Rust

Alliance Access LAU Sign Message (XML Signature using HMAC-SHA-256)

See more XML Digital Signatures Examples

Demonstrates how to sign XML according to the requirements for Alliance Access LAU (Local Authentication) using HMAC-SHA-256.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// We begin with this message:

// <?xml version="1.0" encoding="utf-8"?>
// <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
//   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
//     <Saa:Revision>2.0.7</Saa:Revision>
//     <Saa:Header>
//         <Saa:Message>
// 			<test>blah blah</test>
//         </Saa:Message>
//     </Saa:Header>
//     <Saa:Body>...</Saa:Body>
//     <Saa:LAU>
//     </Saa:LAU>
// </Saa:DataPDU>

// And we want so sign to create this as the result:
// The signed XML we'll create will not be indented and pretty-printed like this.
// Instead, we'll use the "CompactSignedXml" behavior to produce compact single-line XML.

// <?xml version="1.0" encoding="utf-8"?>
// <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
//   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
//     <Saa:Revision>2.0.7</Saa:Revision>
//     <Saa:Header>
//         <Saa:Message>
// 			<test>blah blah</test>
//         </Saa:Message>
//     </Saa:Header>
//     <Saa:Body>...</Saa:Body>
//     <Saa:LAU>
//         <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
//             <ds:SignedInfo>
//                 <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
//                 <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#hmac-sha256"/>
//                 <ds:Reference URI="">
//                     <ds:Transforms>
//                         <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
//                         <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
//                     </ds:Transforms>
//                     <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
//                     <ds:DigestValue>Y7oScHnYOUQvni/TSzZbDec+HR+mWIFH149GXpwj1Ws=</ds:DigestValue>
//                 </ds:Reference>
//             </ds:SignedInfo>
//             <ds:SignatureValue>6ynF/FcwbPsHrtlj3h2agJigdnvpbO6hOzKSRGzqkw0=</ds:SignatureValue>
//         </ds:Signature>
//     </Saa:LAU>
// </Saa:DataPDU>

let _ = true;

// Create the XML to be signed...

// (The XML does not need to be created this way.  It can be loaded from a file or a string.)
// Also, use this online tool to generate code from sample XML: 
// Generate Code to Create XML

let xml_to_sign = chilkat::Xml::new();
xml_to_sign.set_tag("Saa:DataPDU");
let _ = xml_to_sign.add_attribute("xmlns:Saa", "urn:swift:saa:xsd:saa.2.0");
let _ = xml_to_sign.add_attribute("xmlns:Sw", "urn:swift:snl:ns.Sw");
let _ = xml_to_sign.add_attribute("xmlns:SwGbl", "urn:swift:snl:ns.SwGbl");
let _ = xml_to_sign.add_attribute("xmlns:SwInt", "urn:swift:snl:ns:SwInt");
let _ = xml_to_sign.add_attribute("xmlns:SwSec", "url:swift:snl:ns.SwSec");
xml_to_sign.update_child_content("Saa:Revision", "2.0.7");
xml_to_sign.update_child_content("Saa:Header|Saa:Message|test", "blah blah");
xml_to_sign.update_child_content("Saa:Body", "...");
xml_to_sign.update_child_content("Saa:LAU", "");

let gen_ = chilkat::XmlDSigGen::new();

gen_.set_sig_location("Saa:DataPDU|Saa:LAU");
gen_.set_sig_location_mod(0);
gen_.set_sig_namespace_prefix("ds");
gen_.set_sig_namespace_uri("http://www.w3.org/2000/09/xmldsig#");
gen_.set_signed_info_canon_alg("EXCL_C14N");
gen_.set_signed_info_digest_method("sha256");

// You may alternatively choose "IndentedSignature" instead of "CompactSignedXml"
gen_.set_behaviors("CompactSignedXml");

let _ = gen_.add_same_doc_ref("", "sha256", "EXCL_C14N", "", "");

// Specify the HMAC key.
// For example, if the HMAC key is to be the us-ascii bytes of the string "secret",
// the HMAC key can be set in any of the following ways (and also more ways not shown here..)
let _ = gen_.set_hmac_key("secret", "ascii");
// or
let _ = gen_.set_hmac_key("c2VjcmV0", "base64");
// or
let _ = gen_.set_hmac_key("736563726574", "hex");

// Sign the XML..
let sb_xml = chilkat::StringBuilder::new();
let _ = xml_to_sign.get_xml_sb(&sb_xml);
if gen_.create_xml_d_sig_sb(&sb_xml).is_err() {
    println!("{}", gen_.last_error_text());
    return;
}

// Save the signed XML to a file.
let _ = sb_xml.write_file("qa_output/signedXml.xml", "utf-8", false).is_ok();

// Show the signed XML.
println!("{}", sb_xml.get_as_string().unwrap_or_default());