Sample code for 30+ languages & platforms
Zig

Create CAdES-T Signature using Aruba TSA Server (servizi.arubapec.it)

See more CAdES Examples

Demonstrates how to create a signature with an external timestamp (using the Aruba TSA Server) that certifies the time of signing.

Note: This example requires Chilkat v9.5.0.79 or greater.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    // This example will use a certificate + private key from a .pfx/.p12 file.
    // On Windows systems, it is also possible to use certs on smartcards/usb tokens or certs pre-installed in the Windows registry.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    const pfx_path = "qa_data/pfx/myCertAndKey.p12";
    const pfx_password = "test123";

    cert.loadPfxFile(pfx_path, pfx_password) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    try crypt.setSigningCert(cert);

    // Use SHA-256 rather than the default of SHA-1
    crypt.setHashAlgorithm("sha256");

    // Create JSON that tells Chilkat what signing attributes to include:
    const attrs = try chilkat.JsonObject.init();
    defer attrs.deinit();
    attrs.updateBool("contentType", true) catch {};
    attrs.updateBool("signingTime", true) catch {};
    attrs.updateBool("messageDigest", true) catch {};
    attrs.updateBool("signingCertificateV2", true) catch {};

    // A CAdES-T signature is one that includes a timestampToken created by an online TSA (time stamping authority).
    // We must include the TSA's URL, as well as a few options to indicate what is desired.
    // This example uses the Aruba TSA server, which requires a login/password for the HTTPS request.
    attrs.updateBool("timestampToken.enabled", true) catch {};
    attrs.updateString("timestampToken.tsaUrl", "https://servizi.arubapec.it/tsa/ngrequest.php") catch {};

    // The tsaUsername/tsaPassword feature was added in Chilkat v9.5.0.79.
    // Make sure you are using a version of Chilkat that is no older than v9.5.0.79
    attrs.updateString("timestampToken.tsaUsername", "arubaTsaUsername") catch {};
    attrs.updateString("timestampToken.tsaPassword", "arubaTsaPassword") catch {};

    attrs.updateBool("timestampToken.addNonce", false) catch {};
    attrs.updateBool("timestampToken.requestTsaCert", true) catch {};
    attrs.updateString("timestampToken.hashAlg", "sha256") catch {};

    crypt.setSigningAttributes(try attrs.emit(alloc));

    const in_file = "qa_data/json/sample.json";
    const out_file = "qa_output/sample_cades_t.p7m";

    // This creates the CAdES-T signature.  During the signature creation, it
    // communicates with the TSA to get a timestampToken.
    crypt.createP7M(in_file, out_file) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});
}