PLBuildModernDetachedCMS

Cryptography, digital signatures

Description

Builds a detached CMS SignedData around RSA, ECDSA or Ed25519 signatures for the algorithms the Windows CryptoAPI message layer cannot express

The signer certificate and its chain context, the digest algorithm, commitment type and signature policy DERs, revocation material and the padding policy all arrive through parameters, with CNG NCrypt, an external digest signer callback or the pure-Pascal Ed25519 path supplying the raw signature

Syntax

Delphi

Function PLBuildModernDetachedCMS(CertContext: Pointer;
  Const CertificateDER, Ed25519Seed, Data, SubFilter: AnsiString;
  DigestAlgorithm: Integer; Const CommitmentTypeDER,
  SignaturePolicyDER: AnsiString; NCryptKeyHandle: TPLIntPtr= 0;
  AllowPrivateKeyUI: Boolean= False;
  ExternalSigner: TPDFlibExternalDigestSignEvent= Nil;
  ExternalSender: TObject= Nil; ExternalSignProcessID: Integer= 0;
  ExternalSignatureAlgorithm: Integer= 0;
  RSAPSSPadding: Boolean= False;
  Const RevocationInfoDER: AnsiString= ''): AnsiString;

Parameters

CertContextWindows CERT_CONTEXT handle of the signing certificate; Nil for the pure external-signer path
CertificateDERDER-encoded signing certificate, used for the embedded certificate and issuer/serial references
Ed25519Seed32-byte seed when signing Ed25519 without CNG, otherwise empty
DataThe already digested range bytes the detached signature covers
SubFilterTarget /SubFilter such as /ETSI.CAdES.detached driving attribute selection
DigestAlgorithmDigest algorithm ordinal matching Ord(TPDFlibDigestAlgorithm): 2 SHA-256, 3 SHA-384, 4 SHA-512, 5 to 7 the SHA-3 family
CommitmentTypeDERDER-encoded commitment type attribute, empty when none
SignaturePolicyDERDER-encoded signature policy identifier, empty when none
NCryptKeyHandleOpen CNG key handle; 0 lets the function open the certificate private key itself, optionally showing the UI
AllowPrivateKeyUIPermits the CNG key acquisition dialogue when the key requires user presence
ExternalSignerCallback receiving the digest and returning the raw signature, for HSM or remote signing
ExternalSenderSender passed back to the ExternalSigner callback
ExternalSignProcessIDSign process identifier passed back to the callback
ExternalSignatureAlgorithmOne of PL_EXTERNAL_SIGNATURE_RSA_PKCS1, PL_EXTERNAL_SIGNATURE_ECDSA_DER, PL_EXTERNAL_SIGNATURE_ECDSA_P1363
RSAPSSPaddingSelects RSASSA-PSS padding for RSA signatures
RevocationInfoDERPre-collected revocation info to embed as RevocationInfoChoices

Return value

The DER-encoded detached CMS, or an empty string when any signing step fails

Remarks

This routine is the engine behind the modern-signature paths of the sign process; calling it directly keeps full control over commitment and policy attributes while the returned bytes slot into the PDF /Contents hole as with PLIsModernDetachedCMS-verified data

See also

PLVerifyModernDetachedCMS, PLIsModernDetachedCMS, PLModernSignatureSizeEstimate, TPDFlibExternalDigestSignEvent, SetSignProcessExternalDigestSigner