Sample code for 30+ languages & platforms
Tcl

Create CAdES p7m using AWS KMS to Sign in the Cloud

See more Signing in the Cloud Examples

Demonstrates how to create a CAdES p7m, using AWS KMS. The signing of the hash happens in the Cloud on AWS KMS. Everything else regarding the creation of CAdES happens locally within Chilkat.

Note: This example requires Chilkat v9.5.0.96 or greater.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example assumes the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Load the certificate used for signing.  The certificate's private key is stored in AWS KMS
# However, we still need the certificate locally (without private key).
set cert [new_CkCert]

set success [CkCert_LoadFromFile $cert "qa_data/certs/myCert.cer"]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCert $cert
    exit
}

# Here's a screenshot showing the key ID of a private key in AWS KMS:
# (image:https://example-code.com/images/aws_kms.jpg/endImage)

# To sign using AWS KMS, 
# add the following lines of code to specify your AWS authentication credentials,
# and the ID of the KMS private key.
set jsonAwsKms [new_CkJsonObject]

# Set the "service" equal to "aws_kms" to tell Chilkat to use AWS KMS for signing.
CkJsonObject_UpdateString $jsonAwsKms "service" "aws_kms"
CkJsonObject_UpdateString $jsonAwsKms "access_key" "ACCESS_KEY"
CkJsonObject_UpdateString $jsonAwsKms "secret_key" "SECRET_KEY"
# Make sure to specify the correct region for your case.
CkJsonObject_UpdateString $jsonAwsKms "region" "us-west-2"
# In the above screenshot, our key ID is "187012e8-008f-4fc7-b100-5efe6146dff2".  You will use your key ID.
CkJsonObject_UpdateString $jsonAwsKms "key_id" "187012e8-008f-4fc7-b100-5efe6146dff2"

set success [CkCert_SetCloudSigner $cert $jsonAwsKms]

set crypt [new_CkCrypt2]

set success [CkCrypt2_SetSigningCert $crypt $cert]
if {$success == 0} then {
    puts [CkCrypt2_lastErrorText $crypt]
    delete_CkCert $cert
    delete_CkJsonObject $jsonAwsKms
    delete_CkCrypt2 $crypt
    exit
}

# The CadesEnabled property applies to all methods that create PKCS7 signatures. 
# To create a CAdES-BES signature, set this property equal to true.
CkCrypt2_put_CadesEnabled $crypt 1

CkCrypt2_put_HashAlgorithm $crypt "sha256"

set signedAttrs [new_CkJsonObject]

CkJsonObject_UpdateInt $signedAttrs "contentType" 1
CkJsonObject_UpdateInt $signedAttrs "signingTime" 1
CkJsonObject_UpdateInt $signedAttrs "messageDigest" 1
CkJsonObject_UpdateInt $signedAttrs "signingCertificateV2" 1
CkCrypt2_put_SigningAttributes $crypt [CkJsonObject_emit $signedAttrs]

# You can sign any type of file..
set inputXmlPath "qa_data/e-Invoice.xml"
set outputP7mPath "qa_output/signed.p7m"

# Create the CAdES-BES attached signature, which contains the original data.
# Chilkat will build the .p7m locally, but will (internally) use ARSS
# to do the RSA signing remotely.
set success [CkCrypt2_CreateP7M $crypt $inputXmlPath $outputP7mPath]
if {$success == 0} then {
    puts [CkCrypt2_lastErrorText $crypt]
    delete_CkCert $cert
    delete_CkJsonObject $jsonAwsKms
    delete_CkCrypt2 $crypt
    delete_CkJsonObject $signedAttrs
    exit
}

puts "Success."

delete_CkCert $cert
delete_CkJsonObject $jsonAwsKms
delete_CkCrypt2 $crypt
delete_CkJsonObject $signedAttrs