Xbase++
Xbase++
Create JWS with Multiple Signatures using the General JSON Serialization Format
See more JSON Web Signatures (JWS) Examples
Creates a JSON Web Signature (JWS) containing 3 signatures and output using the general JSON serialization format.Chilkat supports all of the following JWS algorithms:
+--------------+-------------------------------+--------------------+ | "alg" Param | Digital Signature or MAC | Implementation | | Value | Algorithm | Requirements | +--------------+-------------------------------+--------------------+ | HS256 | HMAC using SHA-256 | Required | | HS384 | HMAC using SHA-384 | Optional | | HS512 | HMAC using SHA-512 | Optional | | RS256 | RSASSA-PKCS1-v1_5 using | Recommended | | | SHA-256 | | | RS384 | RSASSA-PKCS1-v1_5 using | Optional | | | SHA-384 | | | RS512 | RSASSA-PKCS1-v1_5 using | Optional | | | SHA-512 | | | ES256 | ECDSA using P-256 and SHA-256 | Recommended+ | | ES384 | ECDSA using P-384 and SHA-384 | Optional | | ES512 | ECDSA using P-521 and SHA-512 | Optional | | PS256 | RSASSA-PSS using SHA-256 and | Optional | | | MGF1 with SHA-256 | | | PS384 | RSASSA-PSS using SHA-384 and | Optional | | | MGF1 with SHA-384 | | | PS512 | RSASSA-PSS using SHA-512 and | Optional | | | MGF1 with SHA-512 | | +--------------+-------------------------------+--------------------+
Note: This example requires Chilkat v9.5.0.66 or greater.
Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oSbRsaJwk
LOCAL oRsaKey
LOCAL oSbEccJwk
LOCAL oEccKey
LOCAL cHmacKey
LOCAL oJwsProtHdr0
LOCAL oJwsUnprotHdr0
LOCAL oJwsProtHdr1
LOCAL oJwsUnprotHdr1
LOCAL oJwsProtHdr2
LOCAL oJwsUnprotHdr2
LOCAL oJws
LOCAL nBIncludeBom
LOCAL cPayloadStr
LOCAL cJwsStr
LOCAL oJson
nSuccess := 0
// This requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Note: This example requires Chilkat v9.5.0.66 or greater.
// The JWS to be created will contain three signatures.
// The 1st will use an ECC key, the 2nd an RSA key, and the 3rd an HMAC key.
// Prepare each key..
// ---------------------------------------------------
// Use the following RSA key loaded from JWK format.
oSbRsaJwk := CreateObject("Chilkat.StringBuilder")
oSbRsaJwk:Append('{"kty":"RSA",')
oSbRsaJwk:Append('"n":"ofgWCuLjybRlzo0tZWJjNiuSfb4p4fAkd_wWJcyQoTbji9k0l8W26mPddx')
oSbRsaJwk:Append("HmfHQp-Vaw-4qPCJrcS2mJPMEzP1Pt0Bm4d4QlL-yRT-SFd2lZS-pCgNMs")
oSbRsaJwk:Append("D1W_YpRPEwOWvG6b32690r2jZ47soMZo9wGzjb_7OMg0LOL-bSf63kpaSH")
oSbRsaJwk:Append("SXndS5z5rexMdbBYUsLA9e-KXBdQOS-UTo7WTBEMa2R2CapHg665xsmtdV")
oSbRsaJwk:Append("MTBQY4uDZlxvb3qCo5ZwKh9kG4LT6_I5IhlJH7aGhyxXFvUK-DWNmoudF8")
oSbRsaJwk:Append('NAco9_h9iaGNj8q2ethFkMLs91kzk2PAcDTW9gb54h4FRWyuXpoQ",')
oSbRsaJwk:Append('"e":"AQAB",')
oSbRsaJwk:Append('"d":"Eq5xpGnNCivDflJsRQBXHx1hdR1k6Ulwe2JZD50LpXyWPEAeP88vLNO97I')
oSbRsaJwk:Append("jlA7_GQ5sLKMgvfTeXZx9SE-7YwVol2NXOoAJe46sui395IW_GO-pWJ1O0")
oSbRsaJwk:Append("BkTGoVEn2bKVRUCgu-GjBVaYLU6f3l9kJfFNS3E0QbVdxzubSu3Mkqzjkn")
oSbRsaJwk:Append("439X0M_V51gfpRLI9JYanrC4D4qAdGcopV_0ZHHzQlBjudU2QvXt4ehNYT")
oSbRsaJwk:Append("CBr6XCLQUShb1juUO1ZdiYoFaFQT5Tw8bGUl_x_jTj3ccPDVZFD9pIuhLh")
oSbRsaJwk:Append('BOneufuBiB4cS98l2SR_RQyGWSeWjnczT0QU91p1DhOVRuOopznQ",')
oSbRsaJwk:Append('"p":"4BzEEOtIpmVdVEZNCqS7baC4crd0pqnRH_5IB3jw3bcxGn6QLvnEtfdUdi')
oSbRsaJwk:Append("YrqBdss1l58BQ3KhooKeQTa9AB0Hw_Py5PJdTJNPY8cQn7ouZ2KKDcmnPG")
oSbRsaJwk:Append('BY5t7yLc1QlQ5xHdwW1VhvKn-nXqhJTBgIPgtldC-KDV5z-y2XDwGUc",')
oSbRsaJwk:Append('"q":"uQPEfgmVtjL0Uyyx88GZFF1fOunH3-7cepKmtH4pxhtCoHqpWmT8YAmZxa')
oSbRsaJwk:Append("ewHgHAjLYsp1ZSe7zFYHj7C6ul7TjeLQeZD_YwD66t62wDmpe_HlB-TnBA")
oSbRsaJwk:Append('-njbglfIsRLtXlnDzQkv5dTltRJ11BKBBypeeF6689rjcJIDEz9RWdc",')
oSbRsaJwk:Append('"dp":"BwKfV3Akq5_MFZDFZCnW-wzl-CCo83WoZvnLQwCTeDv8uzluRSnm71I3Q')
oSbRsaJwk:Append("CLdhrqE2e9YkxvuxdBfpT_PI7Yz-FOKnu1R6HsJeDCjn12Sk3vmAktV2zb")
oSbRsaJwk:Append('34MCdy7cpdTh_YVr7tss2u6vneTwrA86rZtu5Mbr1C1XsmvkxHQAdYo0",')
oSbRsaJwk:Append('"dq":"h_96-mK1R_7glhsum81dZxjTnYynPbZpHziZjeeHcXYsXaaMwkOlODsWa')
oSbRsaJwk:Append("7I9xXDoRwbKgB719rrmI2oKr6N3Do9U0ajaHF-NKJnwgjMd2w9cjz3_-ky")
oSbRsaJwk:Append('NlxAr2v4IKhGNpmM5iIgOS1VZnOZ68m6_pbLBSp3nssTdlqvd0tIiTHU",')
oSbRsaJwk:Append('"qi":"IYd7DHOhrWvxkwPQsRM2tOgrjbcrfvtQJipd-DlcxyVuuM9sQLdgjVk2o')
oSbRsaJwk:Append("y26F0EmpScGLq2MowX7fhd_QJQ3ydy5cY7YIBi87w93IKLEdfnbJtoOPLU")
oSbRsaJwk:Append('W0ITrJReOgo1cq9SbsxYawBgfp_gh6A5603k2-ZQwVK0JKSHuLFkuQ3U"')
oSbRsaJwk:Append("}")
oRsaKey := CreateObject("Chilkat.PrivateKey")
// Note: This example loads the RSA key from JWK format. Any format can be loaded
// into the private key object. (See the online reference documentation..)
nSuccess := oRsaKey:LoadJwk(oSbRsaJwk:GetAsString())
IF (nSuccess != 1)
? oRsaKey:LastErrorText
oSbRsaJwk:destroy()
oRsaKey:destroy()
RETURN
ENDIF
// ---------------------------------------------------
// Use the following ECC key loaded from JWK format.
oSbEccJwk := CreateObject("Chilkat.StringBuilder")
oSbEccJwk:Append('{"kty":"EC",')
oSbEccJwk:Append('"crv":"P-256",')
oSbEccJwk:Append('"x":"f83OJ3D2xF1Bg8vub9tLe1gHMzV76e8Tus9uPHvRVEU",')
oSbEccJwk:Append('"y":"x_FEzRu9m36HLN_tue659LNpXW6pCyStikYjKIWI5a0",')
oSbEccJwk:Append('"d":"jpsQnnGQmL-YBIffH1136cspYG6-0iY7X1fCE9-E9LI"')
oSbEccJwk:Append("}")
oEccKey := CreateObject("Chilkat.PrivateKey")
// Note: This example loads the ECDSA key from JWK format. Any format can be loaded
// into the private key object. (See the online reference documentation..)
nSuccess := oEccKey:LoadJwk(oSbEccJwk:GetAsString())
IF (nSuccess != 1)
? oEccKey:LastErrorText
oSbRsaJwk:destroy()
oRsaKey:destroy()
oSbEccJwk:destroy()
oEccKey:destroy()
RETURN
ENDIF
// ---------------------------------------------------
// The HMAC key (in base64url format)
cHmacKey := "AyM1SysPpbyDfgZld3umj1qzKObwVMkoqQ-EstJQLr_T-1qS0gZH75aKtMN3Yj0iPS4hcgUuTwjAzZr1Z9CAow"
// ---------------------------------------------------
// Prepare the headers..
// RSASSA-PKCS1-v1_5 SHA-256
oJwsProtHdr0 := CreateObject("Chilkat.JsonObject")
oJwsProtHdr0:AppendString("alg", "RS256")
oJwsUnprotHdr0 := CreateObject("Chilkat.JsonObject")
oJwsUnprotHdr0:AppendString("kid", "myRsaKey")
// ECDSA using P-256 and SHA-256
oJwsProtHdr1 := CreateObject("Chilkat.JsonObject")
oJwsProtHdr1:AppendString("alg", "ES256")
oJwsUnprotHdr1 := CreateObject("Chilkat.JsonObject")
oJwsUnprotHdr1:AppendString("kid", "myEcKey")
// HMAC using SHA-256
oJwsProtHdr2 := CreateObject("Chilkat.JsonObject")
oJwsProtHdr2:AppendString("alg", "HS256")
oJwsUnprotHdr2 := CreateObject("Chilkat.JsonObject")
oJwsUnprotHdr2:AppendString("kid", "myMacKey")
// ---------------------------------------------------
// First set the JWS headers, keys, and payload, then we'll create the JWS...
oJws := CreateObject("Chilkat.Jws")
oJws:SetProtectedHeader(0, oJwsProtHdr0)
oJws:SetUnprotectedHeader(0, oJwsUnprotHdr0)
oJws:SetProtectedHeader(1, oJwsProtHdr1)
oJws:SetUnprotectedHeader(1, oJwsUnprotHdr1)
oJws:SetProtectedHeader(2, oJwsProtHdr2)
oJws:SetUnprotectedHeader(2, oJwsUnprotHdr2)
oJws:SetPrivateKey(0, oRsaKey)
oJws:SetPrivateKey(1, oEccKey)
oJws:SetMacKey(2, cHmacKey, "base64url")
nBIncludeBom := 0
cPayloadStr := "In our village, folks say God crumbles up the old moon into stars."
oJws:SetPayload(cPayloadStr, "utf-8", nBIncludeBom)
// ---------------------------------------------------
// Create the JWS.
// Givent that multiple signatures will exist, only the general JSON serialization
// format is possible, and that is what will be produced.
cJwsStr := oJws:CreateJws()
IF (oJws:LastMethodSuccess != 1)
? oJws:LastErrorText
oSbRsaJwk:destroy()
oRsaKey:destroy()
oSbEccJwk:destroy()
oEccKey:destroy()
oJwsProtHdr0:destroy()
oJwsUnprotHdr0:destroy()
oJwsProtHdr1:destroy()
oJwsUnprotHdr1:destroy()
oJwsProtHdr2:destroy()
oJwsUnprotHdr2:destroy()
oJws:destroy()
RETURN
ENDIF
// The jwsStr is contains JSON in the smallest possible size, which is a single line.
// To get in human-readable format, load into a Chilkat JSON object and emit..
oJson := CreateObject("Chilkat.JsonObject")
oJson:Load(cJwsStr)
oJson:EmitCompact := 0
? oJson:Emit()
// Sample output:
// {
// "payload": "SW4gb3VyIHZpbGxhZ2UsIGZvbGtzIHNheSBHb2QgY3J1bWJsZXMgdXAgdGhlIG9sZCBtb29uIGludG8gc3RhcnMu",
// "signatures": [
// {
// "protected": "eyJhbGciOiJSUzI1NiJ9",
// "header": {
// "kid": "myRsaKey"
// },
// "signature": "B04c24gSnpVm1Z-_bemfyNMCpZm6Knj1yB-yzaIOvijsWfDgoF_mSJccTIbzapNgwJudnobr5iDOfZWiRR9iqCyDJLe5M1S40vFF7MFEI3JecYRgrRc6n1lTkYLMRyVq48BwbQlmKgPqmK9drun3agklsr0FmgNx65pfmcnlYdXsgwxf8WbgppefrlrMImp-98-dNtBcUL8ce1aOjbcyVFjGMCzpm3JerQqIzWQvEwBstnMEQle73KHcyx_nsTmlzY70CaydbRTsciOATL7WfiMwuX1q9Y2NIpTg3CbOTWKdwjh7iyfiAKQxNBaF2mApnqj9hjpf8GwR-CfxAzJtPg"
// },
// {
// "protected": "eyJhbGciOiJFUzI1NiJ9",
// "header": {
// "kid": "myEcKey"
// },
// "signature": "2cbugKq0ERaQMh01n2B-86EZFYleeMf8bsccaQMxzOxAg14PxfjR3IImvodTJYqkmfBJYW203etz2-7ZtJUOGw"
// },
// {
// "protected": "eyJhbGciOiJIUzI1NiJ9",
// "header": {
// "kid": "myMacKey"
// },
// "signature": "e7R9gjx0RsUNa3c7qd8k9mQGEhtcG8vsN1W7jbLb2MA"
// }
// ]
// }
oSbRsaJwk:destroy()
oRsaKey:destroy()
oSbEccJwk:destroy()
oEccKey:destroy()
oJwsProtHdr0:destroy()
oJwsUnprotHdr0:destroy()
oJwsProtHdr1:destroy()
oJwsUnprotHdr1:destroy()
oJwsProtHdr2:destroy()
oJwsUnprotHdr2:destroy()
oJws:destroy()
oJson:destroy()