SetSignProcessCNGKeyByHandle

Security and signatures

Description

Attaches a caller-owned NCRYPT_KEY_HANDLE and its DER-encoded X.509 certificate to a PDF signing process

This path supports keys opened by application-specific discovery, policy, or cloud-provider code without reopening the key by name

Syntax

Delphi

Function TPDFlib.SetSignProcessCNGKeyByHandle(SignProcessID: Integer; Const CertificateDER: AnsiString; KeyHandle: TPLIntPtr; AllowUI: Boolean): Integer;

Parameters

CertificateDERComplete DER-encoded RSA or ECDSA X.509 certificate corresponding to the key
KeyHandleOpen NCRYPT_KEY_HANDLE represented as TPLIntPtr
AllowUITrue to permit provider interaction while signing

Return values

1The borrowed handle was attached to the process
0The process id, certificate, or handle was invalid

Remarks

The caller retains ownership and must keep the handle valid until EndSignProcessTo* completes

The library queries the NCrypt algorithm group before signing and verifies the finished CMS signature against the supplied certificate

This handle-sized API is Delphi-only; DLL and ActiveX callers use the provider-and-key-name APIs

See also

SetSignProcessCNGKey, SetSignProcessPrivateKeyUI