TPDFlibPFXFile
Security and Signatures
Description
TPDFlibPFXFile holds the signing identity used to produce a detached PKCS#7 signature
The identity can come from a PFX file, a Windows system certificate store entry resolved by its simple display name, an externally duplicated PCCERT_CONTEXT, an Ed25519 key pair, a CNG key, or an external digest callback
Once an identity is bound, SignData produces the CMS signature bytes and the estimate helpers size the /Contents reservation before the signature is written
The SigningWorkbench demo opens a PFX with this class before handing the identity to the signing pipeline
Syntax
Delphi
TPDFlibPFXFile = Class
Public
Destructor Destroy; Override;
Function Open(Const FileName: WideString; Const Password: AnsiString; UseMachineKeyset: Boolean): TPDFlibSignerResult;
Function OpenFromStore(Const StoreName, CertName: WideString; UseMachineStore: Boolean): TPDFlibSignerResult;
Function EnumerateStore(Const StoreName: WideString; UseMachineStore: Boolean;
Var Infos: Array Of TPDFlibCertificateInfo): Integer;
Function OpenFromContext(CertContext: Pointer): TPDFlibSignerResult;
Function OpenEd25519(Const CertificateDER, PrivateKeyDER: AnsiString): TPDFlibSignerResult;
Function OpenEd25519FromFile(Const CertificateFile, PrivateKeyFile: WideString): TPDFlibSignerResult;
Function OpenCNGKey(Const CertificateDER: AnsiString;
Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): TPDFlibSignerResult;
Function OpenCNGKeyHandle(Const CertificateDER: AnsiString; KeyHandle: TPLIntPtr; AllowUI: Boolean): TPDFlibSignerResult;
Function OpenExternalDigestSigner(Const CertificateDER: AnsiString;
Signer: TPDFlibExternalDigestSignEvent; Sender: TObject;
SignProcessID, SignatureAlgorithm, SignatureReserveBytes: Integer): TPDFlibSignerResult;
Function GetCertificateDER: AnsiString;
Procedure SetPrivateKeyUI(AllowUI: Boolean);
Procedure SetRSAPSSPadding(Enable: Boolean);
Function CertificateKeyUsage: Integer;
Function EstimateSignatureSize(Const Data, SubFilter: AnsiString;
DigestAlgorithm: TPDFlibDigestAlgorithm;
Const CommitmentTypeDER, SignaturePolicyDER, RevocationInfoDER: AnsiString): Integer;
Function EstimateCertificateChainSize: Integer;
Function SignData(Const Data, SubFilter: AnsiString; DigestAlgorithm: TPDFlibDigestAlgorithm;
Const CommitmentTypeDER, SignaturePolicyDER, RevocationInfoDER: AnsiString): AnsiString;
End;Methods
| Open | Loads a PFX or PKCS#12 file with its password; UseMachineKeyset selects the machine key set |
|---|---|
| OpenFromStore | Locates a certificate in a Windows system store by Subject simple display name and binds its context; the first certificate that carries a usable private key wins |
| EnumerateStore | Fills the caller-supplied array with one TPDFlibCertificateInfo per store certificate and returns the count actually filled |
| OpenFromContext | Binds an externally obtained PCCERT_CONTEXT; the caller keeps ownership and must keep the context valid until signing completes |
| OpenEd25519, OpenEd25519FromFile | Bind an Ed25519 certificate and seed from memory or from files |
| OpenCNGKey, OpenCNGKeyHandle | Bind a CNG-backed key by provider and key name, or by an existing key handle |
| OpenExternalDigestSigner | Signs through the TPDFlibExternalDigestSignEvent callback instead of a local private key |
| GetCertificateDER | The bound certificate in DER form |
| SetPrivateKeyUI | Allows or suppresses the CryptoAPI private-key prompt |
| SetRSAPSSPadding | Selects RSASSA-PSS padding for RSA detached signatures; legacy CryptoAPI keys keep PKCS#1 v1.5 |
| CertificateKeyUsage | The X.509 key-usage bits packed as two bytes, or -1 when no context is bound |
| EstimateSignatureSize, EstimateCertificateChainSize | Upper bounds for the CMS output and the certificate chain |
| SignData | Produces the detached CMS signature for the data with the selected sub-filter and digest algorithm |
Remarks
All open methods return TPDFlibSignerResult, so a failed identity binding can be reported precisely
The facade reaches the same identities through SetSignProcessPFXFromFile, SetSignProcessCertFromStore, SetSignProcessEd25519Identity and SetSignProcessCNGKey
See also
TPDFlibSignerResult, TPDFlibCertificateInfo, TPDFlibSigner, TPDFlibSignDoc, NewSignProcessFromFile