SetSignProcessContentsEstimate

Security and signatures

Description

Configures the material sizes and safety margin used to estimate the signature /Contents capacity

The estimator combines the base CMS size with certificate-chain, revocation, and time-stamp requirements before the signature field is written

Syntax

Delphi

Function TPDFlib.SetSignProcessContentsEstimate(SignProcessID, CertificateChainBytes, CRLBytes, OCSPBytes, TimeStampTokenBytes, SafetyMarginPercent: Integer): Integer;

ActiveX

Function PDFlib::SetSignProcessContentsEstimate(SignProcessID As Long, CertificateChainBytes As Long, CRLBytes As Long, OCSPBytes As Long, TimeStampTokenBytes As Long, SafetyMarginPercent As Long) As Long

DLL

int DLSetSignProcessContentsEstimate(int InstanceID, int SignProcessID, int CertificateChainBytes, int CRLBytes, int OCSPBytes, int TimeStampTokenBytes, int SafetyMarginPercent);

Parameters

SignProcessIDValue returned by a NewSignProcessFrom* function
CertificateChainBytesPass -1 to discover the remaining certificate chain from local Windows caches, 0 to omit additional chain capacity, or a positive value to supply an expected encoded size
CRLBytesTotal expected DER bytes for planned certificate revocation lists
OCSPBytesTotal expected DER bytes for planned OCSP responses
TimeStampTokenBytesExpected DER size of a planned RFC 3161 time-stamp token
SafetyMarginPercentAdditional percentage from 0 through 100 applied before alignment

Return values

1The estimate configuration was accepted
0The process id, material size, aggregate size, or percentage was invalid

Remarks

A new sign process defaults to cached-chain discovery, no planned revocation or time-stamp material, and a 15 percent safety margin

Local PFX signing uses a measured CMS size, while system-store, CNG, Ed25519, and external-digest signing derive the maximum signature size from the certificate public key without invoking a private key or callback

Certificate-chain discovery is cache-only and never performs network retrieval

The result is aligned to 256 bytes and capped at 64 MiB, and SetSignProcessReserveContentsBytes remains an additive manual reserve

See also

GetSignProcessEstimatedContentsBytes, SetSignProcessReserveContentsBytes, SetPAdESSignatureTimeStampToken