Sample code for 30+ languages & platforms
Zig

Create XAdES using Smart Card or USB Token

See more XAdES Examples

Demonstrates how to create an XAdES signed XML document using a certificate located on a smartcard or USB token.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // Load the XML to be signed.
    const xml_to_sign = try chilkat.Xml.init();
    defer xml_to_sign.deinit();
    xml_to_sign.loadXmlFile("qa_data/fattura_electronica/docToSign.xml") catch {
        std.debug.print("{s}\n", .{try xml_to_sign.getLastErrorText(alloc)});
        return;
    };

    const gen = try chilkat.XmlDSigGen.init();
    defer gen.deinit();

    gen.setSigLocation("p:FatturaElettronica");
    gen.setSigId("xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504");
    gen.setSigNamespacePrefix("ds");
    gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
    gen.setSigValueId("xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-sigvalue");
    gen.setSignedInfoCanonAlg("C14N");
    gen.setSignedInfoDigestMethod("sha256");

    // Create an Object to be added to the Signature.
    // Note: Chilkat will automatically populate the strings indicated by "TO BE GENERATED BY CHILKAT" with actual/correct values
    // when the XML is signed.
    const object1 = try chilkat.Xml.init();
    defer object1.deinit();
    object1.setTag("xades:QualifyingProperties");
    object1.addAttribute("xmlns:xades", "http://uri.etsi.org/01903/v1.3.2#") catch {};
    object1.addAttribute("xmlns:xades141", "http://uri.etsi.org/01903/v1.4.1#") catch {};
    object1.addAttribute("Target", "#xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504") catch {};
    object1.updateAttrAt("xades:SignedProperties", true, "Id", "xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-signedprops") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningTime", "TO BE GENERATED BY CHILKAT");
    object1.updateAttrAt("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestMethod", true, "Algorithm", "http://www.w3.org/2001/04/xmlenc#sha256") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestValue", "TO BE GENERATED BY CHILKAT");
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:IssuerSerialV2", "TO BE GENERATED BY CHILKAT");

    gen.addObject("", try object1.getXml(alloc), "", "") catch {};

    // -------- Reference 1 --------
    gen.setKeyInfoId("xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-keyinfo");
    gen.addSameDocRef("xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-keyinfo", "sha256", "", "", "") catch {};

    // -------- Reference 2 --------
    gen.addSameDocRef("", "sha256", "", "", "") catch {};
    gen.setRefIdAttr("", "xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-ref0") catch {};

    // -------- Reference 3 --------
    gen.addObjectRef("xmldsig-6f4b994a-7191-4bb1-ab3c-17549515b504-signedprops", "sha256", "", "", "http://uri.etsi.org/01903#SignedProperties") catch {};

    // ----------------------------------------------------------------
    //  Load a certificate that has been pre-installed on the Windows system
    //  This includes certificates on smartcards and USB tokens
    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    //  You may provide the PIN here..
    cert.setSmartCardPin("000000");

    // Load the certificate on the smartcard currently in the reader (or on the USB token).
    // Pass an empty string to allow Chilkat to automatically choose the CSP (Cryptographi Service Provider).
    // See Load Certificate on Smartcard for information about explicitly selecting a particular CSP.
    cert.loadFromSmartcard("") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    gen.setX509Cert(cert, true) catch {};
    gen.setKeyInfoType("X509Data");
    gen.setX509Type("Certificate");

    // Load XML to be signed...
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    xml_to_sign.getXmlSb(sb_xml) catch {};

    gen.setBehaviors("IndentedSignature,ForceAddEnvelopedSignatureTransform");

    // Sign the XML...
    gen.createXmlDSigSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
        return;
    };

    // Save the signed XMl to a file.
    try sb_xml.writeFile("qa_output/signedXml.xml", "utf-8", false);

    std.debug.print("{s}\n", .{try sb_xml.getAsString(alloc)});

    // ----------------------------------------
    // Verify the signature we just produced...
    const verifier = try chilkat.XmlDSig.init();
    defer verifier.deinit();
    verifier.loadSignatureSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    verifier.verifySignature(true) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("This signature was successfully verified.\n", .{});
}