Sample code for 30+ languages & platforms
Unicode C++

Sign JSON to Create CAdES P7S Bytes

See more CAdES Examples

Demonstrates how to sign JSON using a certificate + private key from a .p12/.pfx to create a CAdES P7S byte array.

Chilkat Unicode C++ Downloads

Unicode C++
#include <CkCrypt2W.h>
#include <CkCertW.h>
#include <CkJsonObjectW.h>
#include <CkByteData.h>

void ChilkatSample(void)
    {
    bool success = false;

    //  This example assumes the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    CkCrypt2W crypt;

    CkCertW cert;
    success = cert.LoadPfxFile(L"qa_data/pfx/cert_test123.pfx",L"test123");
    if (success != true) {
        wprintf(L"%s\n",cert.lastErrorText());
        return;
    }

    //  Tell the crypt component to use this cert.
    success = crypt.SetSigningCert(cert);
    if (success != true) {
        wprintf(L"%s\n",crypt.lastErrorText());
        return;
    }

    //  The CadesEnabled property applies to all methods that create PKCS7 signatures. 
    //  To create a CAdES-BES signature, set this property equal to true. 
    crypt.put_CadesEnabled(true);

    crypt.put_HashAlgorithm(L"sha256");

    CkJsonObjectW jsonSigningAttrs;
    jsonSigningAttrs.UpdateInt(L"contentType",1);
    jsonSigningAttrs.UpdateInt(L"signingTime",1);
    jsonSigningAttrs.UpdateInt(L"messageDigest",1);
    jsonSigningAttrs.UpdateInt(L"signingCertificateV2",1);
    crypt.put_SigningAttributes(jsonSigningAttrs.emit());

    //  By default, all the certs in the chain of authentication are included in the signature.
    //  If desired, we can choose to only include the signing certificate:
    crypt.put_IncludeCertChain(false);

    //  Create the CAdES-BES attached signature, which contains the original data.
    crypt.put_Charset(L"utf-8");
    CkByteData cadesP7s;
    success = crypt.OpaqueSignString(L"{ \"abc\": 123}",cadesP7s);
    if (crypt.get_LastMethodSuccess() == false) {
        wprintf(L"%s\n",crypt.lastErrorText());
        return;
    }

    //  Verify the signature and extract the original JSON:
    const wchar_t *originalJson = crypt.opaqueVerifyString(cadesP7s);
    if (crypt.get_LastMethodSuccess() == false) {
        wprintf(L"%s\n",crypt.lastErrorText());
        return;
    }

    wprintf(L"Original JSON: %s\n",originalJson);

    wprintf(L"Success!\n");
    }