PLVerifyModernDetachedCMS
Cryptography, digital signatures
Description
Verifies a signer of a modern detached CMS against the original data bytes
The verifier parses the SignedData, checks the signed-attributes message digest against the data, then validates the raw signature with the signer certificate public key: pure-Pascal Ed25519, ECDSA over the curve parameters, or RSA PKCS#1 and PSS through CNG
Syntax
Delphi
Function PLVerifyModernDetachedCMS(Const CMSBytes, Data: AnsiString;
SignerIndex: Integer; Out SignerCount: Integer;
Out NativeError: Cardinal): Integer;Parameters
| CMSBytes | DER-encoded detached CMS SignedData |
|---|---|
| Data | The original covered bytes, the same input that was digested at signing time |
| SignerIndex | Zero-based signer to verify |
| SignerCount | Receives the number of signers found in the CMS |
| NativeError | Receives a coarse failure class, 13 for malformed input, 50 for digest trouble, or the CNG status of the failed primitive |
Return values
| 0 | The CMS parses but its signature algorithm is not in the modern set, so this verifier is not responsible |
|---|---|
| 1 | The signer verified successfully |
| 2 | A parse, digest or primitive step failed; NativeError carries the reason |
Remarks
Message digest comparison is constant-time and PSS parameters must name the same digest as the SignerInfo, mirroring RFC 4056; result 0 tells the caller to hand the blob to the platform verifier instead
See also
PLBuildModernDetachedCMS, PLIsModernDetachedCMS, PLCertificateSubjectAndIssuer