PLBuildModernDetachedCMS
Cryptography, digital signatures
Description
Builds a detached CMS SignedData around RSA, ECDSA or Ed25519 signatures for the algorithms the Windows CryptoAPI message layer cannot express
The signer certificate and its chain context, the digest algorithm, commitment type and signature policy DERs, revocation material and the padding policy all arrive through parameters, with CNG NCrypt, an external digest signer callback or the pure-Pascal Ed25519 path supplying the raw signature
Syntax
Delphi
Function PLBuildModernDetachedCMS(CertContext: Pointer;
Const CertificateDER, Ed25519Seed, Data, SubFilter: AnsiString;
DigestAlgorithm: Integer; Const CommitmentTypeDER,
SignaturePolicyDER: AnsiString; NCryptKeyHandle: TPLIntPtr= 0;
AllowPrivateKeyUI: Boolean= False;
ExternalSigner: TPDFlibExternalDigestSignEvent= Nil;
ExternalSender: TObject= Nil; ExternalSignProcessID: Integer= 0;
ExternalSignatureAlgorithm: Integer= 0;
RSAPSSPadding: Boolean= False;
Const RevocationInfoDER: AnsiString= ''): AnsiString;Parameters
| CertContext | Windows CERT_CONTEXT handle of the signing certificate; Nil for the pure external-signer path |
|---|---|
| CertificateDER | DER-encoded signing certificate, used for the embedded certificate and issuer/serial references |
| Ed25519Seed | 32-byte seed when signing Ed25519 without CNG, otherwise empty |
| Data | The already digested range bytes the detached signature covers |
| SubFilter | Target /SubFilter such as /ETSI.CAdES.detached driving attribute selection |
| DigestAlgorithm | Digest algorithm ordinal matching Ord(TPDFlibDigestAlgorithm): 2 SHA-256, 3 SHA-384, 4 SHA-512, 5 to 7 the SHA-3 family |
| CommitmentTypeDER | DER-encoded commitment type attribute, empty when none |
| SignaturePolicyDER | DER-encoded signature policy identifier, empty when none |
| NCryptKeyHandle | Open CNG key handle; 0 lets the function open the certificate private key itself, optionally showing the UI |
| AllowPrivateKeyUI | Permits the CNG key acquisition dialogue when the key requires user presence |
| ExternalSigner | Callback receiving the digest and returning the raw signature, for HSM or remote signing |
| ExternalSender | Sender passed back to the ExternalSigner callback |
| ExternalSignProcessID | Sign process identifier passed back to the callback |
| ExternalSignatureAlgorithm | One of PL_EXTERNAL_SIGNATURE_RSA_PKCS1, PL_EXTERNAL_SIGNATURE_ECDSA_DER, PL_EXTERNAL_SIGNATURE_ECDSA_P1363 |
| RSAPSSPadding | Selects RSASSA-PSS padding for RSA signatures |
| RevocationInfoDER | Pre-collected revocation info to embed as RevocationInfoChoices |
Return value
The DER-encoded detached CMS, or an empty string when any signing step fails
Remarks
This routine is the engine behind the modern-signature paths of the sign process; calling it directly keeps full control over commitment and policy attributes while the returned bytes slot into the PDF /Contents hole as with PLIsModernDetachedCMS-verified data
See also
PLVerifyModernDetachedCMS, PLIsModernDetachedCMS, PLModernSignatureSizeEstimate, TPDFlibExternalDigestSignEvent, SetSignProcessExternalDigestSigner