TPDFlibCertificateInfo

Data Types, security and signatures

Description

TPDFlibCertificateInfo is a record returned by EnumCertificates that describes one certificate found in a Windows certificate store. Each entry reports the subject and issuer distinguished names, validity window, whether a private key is available for signing, whether the certificate is eIDAS-qualified, and the raw PCCERT_CONTEXT handle

Syntax

Delphi

type TPDFlibCertificateInfo = record
    Subject: WideString;
    Issuer: WideString;
    SerialNumber: WideString;
    NotBefore: TDateTime;
    NotAfter: TDateTime;
    ValidNow: Boolean;
    HasPrivateKey: Boolean;
    Qualified: Boolean;
    CertHandle: Pointer;
  end;

Fields

SubjectThe subject distinguished name of the certificate
IssuerThe issuer distinguished name of the certificate
SerialNumberThe hexadecimal serial number of the certificate
NotBeforeThe local start of the validity period
NotAfterThe local end of the validity period
ValidNowTrue when the current date falls within the validity window
HasPrivateKeyTrue when the certificate has an associated private key, which is required for signing
QualifiedTrue when the certificate carries the eIDAS QCStatements extension (OID 0.4.0.1862.1.7)
CertHandleThe raw PCCERT_CONTEXT for use with SetSignProcessCertFromStoreByHandle; the store owns it until CertCloseStore is called

Remarks

The certificate store owns the CertHandle; do not close it yourself while the enumeration result is in use

Only certificates with HasPrivateKey set to true can be used as the signer for a signature

See also

EnumCertificates, CreateSelfSignedCertificate, NewSignProcessFromFile