Zig
Zig
Create Egypt ITIDA CAdES-BES .p7s Signature (with strings in-memory)
See more Egypt ITIDA Examples
Demonstrates how to create a .p7s signature that fits Egypt's ITIDA requirements.Note: This example requires Chilkat v9.5.0.75 or greater.
Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
const crypt = try chilkat.Crypt2.init();
defer crypt.deinit();
const cert = try chilkat.Cert.init();
defer cert.deinit();
// There are many ways to load the certificate.
// This example was created for a customer using an ePass2003 USB token.
// Assuming the USB token is the only source of a hardware-based private key..
cert.loadFromSmartcard("") catch {
std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
return;
};
// Tell the crypt component to use this cert.
crypt.setSigningCert(cert) catch {
std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
return;
};
const cms_options = try chilkat.JsonObject.init();
defer cms_options.deinit();
// Setting "DigestData" causes OID 1.2.840.113549.1.7.5 (digestData) to be used.
cms_options.updateBool("DigestData", true) catch {};
cms_options.updateBool("OmitAlgorithmIdNull", true) catch {};
crypt.setCmsOptions(try cms_options.emit(alloc));
// The CadesEnabled property applies to all methods that create CMS/PKCS7 signatures.
// To create a CAdES-BES signature, set this property equal to true.
crypt.setCadesEnabled(true);
crypt.setHashAlgorithm("sha256");
const json_signing_attrs = try chilkat.JsonObject.init();
defer json_signing_attrs.deinit();
json_signing_attrs.updateInt("contentType", 1) catch {};
json_signing_attrs.updateInt("signingTime", 1) catch {};
json_signing_attrs.updateInt("messageDigest", 1) catch {};
json_signing_attrs.updateInt("signingCertificateV2", 1) catch {};
crypt.setSigningAttributes(try json_signing_attrs.emit(alloc));
// By default, all the certs in the chain of authentication are included in the signature.
// If desired, we can choose to only include the signing certificate:
crypt.setIncludeCertChain(false);
// Make sure we sign the utf-8 byte representation of the JSON string
crypt.setCharset("utf-8");
// Create the CAdES-BES signature.
const text_to_sign = "\"issuer\"\"address\"\"branchID\"\"0\"\"country\"\"EG\"\"regionCity...";
crypt.setEncodingMode("base64");
const sig_base64 = crypt.signStringENC(alloc, text_to_sign) catch {
std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
return;
};
std.debug.print("Base64 signature:\n", .{});
std.debug.print("{s}\n", .{sig_base64});
}