PLVerifyModernDetachedCMS

Cryptography, digital signatures

Description

Verifies a signer of a modern detached CMS against the original data bytes

The verifier parses the SignedData, checks the signed-attributes message digest against the data, then validates the raw signature with the signer certificate public key: pure-Pascal Ed25519, ECDSA over the curve parameters, or RSA PKCS#1 and PSS through CNG

Syntax

Delphi

Function PLVerifyModernDetachedCMS(Const CMSBytes, Data: AnsiString;
  SignerIndex: Integer; Out SignerCount: Integer;
  Out NativeError: Cardinal): Integer;

Parameters

CMSBytesDER-encoded detached CMS SignedData
DataThe original covered bytes, the same input that was digested at signing time
SignerIndexZero-based signer to verify
SignerCountReceives the number of signers found in the CMS
NativeErrorReceives a coarse failure class, 13 for malformed input, 50 for digest trouble, or the CNG status of the failed primitive

Return values

0The CMS parses but its signature algorithm is not in the modern set, so this verifier is not responsible
1The signer verified successfully
2A parse, digest or primitive step failed; NativeError carries the reason

Remarks

Message digest comparison is constant-time and PSS parameters must name the same digest as the SignerInfo, mirroring RFC 4056; result 0 tells the caller to hand the blob to the platform verifier instead

See also

PLBuildModernDetachedCMS, PLIsModernDetachedCMS, PLCertificateSubjectAndIssuer