TPDFlibExternalDigestSignEvent

Data types, security and signatures

Description

Function-of-object type for the external digest-sign callback used by the signing pipeline

When TPDFlib.OnExternalDigestSign is assigned, the library calls the handler instead of reaching a private key through CNG: it hands over the digest bytes computed over the data being signed and expects the raw signature bytes back

The callback serves the sign-process family (EndSignProcessToFile, EndSignProcessToStream, EndSignProcessToString) and the signer opened through SetExternalDigestSignCallback; an ECDSA signature supplied in IEEE P1363 raw form is converted to DER by the library

Return True with the signature bytes in Signature to accept; returning False, raising an exception, or leaving Signature empty aborts the signing operation

Declaration

TPDFlibExternalDigestSignEvent = function(Sender: TObject; SignProcessID: Integer; const Digest: AnsiString; DigestAlgorithm, SignatureAlgorithm: Integer; var Signature: AnsiString): Boolean of object;

Parameters

SenderSender object bound to the callback, the owning TPDFlib instance when fired from a sign process
SignProcessIDHandle of the running sign process that requests the signature
DigestRaw digest bytes to be signed as a binary AnsiString
DigestAlgorithmDigest algorithm code: 1 SHA-1, 2 SHA-256, 3 SHA-384, 4 SHA-512, 5 SHA3-256, 6 SHA3-384, 7 SHA3-512
SignatureAlgorithmExpected raw signature layout: PL_EXTERNAL_SIGNATURE_RSA_PKCS1, PL_EXTERNAL_SIGNATURE_ECDSA_DER or PL_EXTERNAL_SIGNATURE_ECDSA_P1363
SignatureVar parameter that receives the raw signature bytes
Return valueTrue on success; any other outcome aborts the operation

See also

OnExternalDigestSign, SetExternalDigestSignCallback, EndSignProcessToFile, EndSignProcessToString, TPDFlib