SetSignProcessExternalDigestSigner

Security and signatures

Description

Attaches a DER-encoded X.509 certificate and an external digest-signing format to a PDF signing process

The library constructs the detached CMS object and sends only the final digest of its authenticated attributes to the registered callback

Syntax

Delphi

Function TPDFlib.SetSignProcessExternalDigestSigner(SignProcessID: Integer; Const CertificateDER: AnsiString; SignatureAlgorithm, SignatureReserveBytes: Integer): Integer;

ActiveX

Function PDFlib::SetSignProcessExternalDigestSigner(SignProcessID As Long, CertificateDER As Variant, SignatureAlgorithm As Long, SignatureReserveBytes As Long) As Long

DLL

int DLSetSignProcessExternalDigestSigner(int InstanceID, int SignProcessID, const char* CertificateDER, int CertificateLength, int SignatureAlgorithm, int SignatureReserveBytes);

Parameters

SignProcessIDValue returned by a NewSignProcessFrom* function
CertificateDERComplete DER-encoded RSA or ECDSA X.509 certificate corresponding to the external private key
SignatureAlgorithm1 for RSA PKCS#1 v1.5, 2 for DER-encoded ECDSA, or 3 for ECDSA P1363 r || s
SignatureReserveBytesExpected upper bound for the raw signature, or 0 to derive it from the certificate public key

Return values

1The external identity configuration was attached
0The process id, certificate, algorithm, or reserve size was invalid

Remarks

Assign OnExternalDigestSign, call DLSetExternalDigestSignCallback, or provide an ActiveX callback object with SetExternalDigestSignCallback before ending the sign process

The callback is not invoked while sizing the /Contents placeholder and is invoked exactly once for the final signature

Returned signature bytes are verified against CertificateDER before the PDF is accepted

When the process still uses the legacy adbe.pkcs7.sha1 default, this method selects adbe.pkcs7.detached automatically

See also

OnExternalDigestSign, SetExternalDigestSignCallback, SetSignProcessContentsEstimate, SetSignProcessExternalDigestSignerFromFile