TPDFlibPFXFile

Security and Signatures

Description

TPDFlibPFXFile holds the signing identity used to produce a detached PKCS#7 signature

The identity can come from a PFX file, a Windows system certificate store entry resolved by its simple display name, an externally duplicated PCCERT_CONTEXT, an Ed25519 key pair, a CNG key, or an external digest callback

Once an identity is bound, SignData produces the CMS signature bytes and the estimate helpers size the /Contents reservation before the signature is written

The SigningWorkbench demo opens a PFX with this class before handing the identity to the signing pipeline

Syntax

Delphi

TPDFlibPFXFile = Class
  Public
    Destructor Destroy; Override;
    Function Open(Const FileName: WideString; Const Password: AnsiString; UseMachineKeyset: Boolean): TPDFlibSignerResult;
    Function OpenFromStore(Const StoreName, CertName: WideString; UseMachineStore: Boolean): TPDFlibSignerResult;
    Function EnumerateStore(Const StoreName: WideString; UseMachineStore: Boolean;
      Var Infos: Array Of TPDFlibCertificateInfo): Integer;
    Function OpenFromContext(CertContext: Pointer): TPDFlibSignerResult;
    Function OpenEd25519(Const CertificateDER, PrivateKeyDER: AnsiString): TPDFlibSignerResult;
    Function OpenEd25519FromFile(Const CertificateFile, PrivateKeyFile: WideString): TPDFlibSignerResult;
    Function OpenCNGKey(Const CertificateDER: AnsiString;
      Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): TPDFlibSignerResult;
    Function OpenCNGKeyHandle(Const CertificateDER: AnsiString; KeyHandle: TPLIntPtr; AllowUI: Boolean): TPDFlibSignerResult;
    Function OpenExternalDigestSigner(Const CertificateDER: AnsiString;
      Signer: TPDFlibExternalDigestSignEvent; Sender: TObject;
      SignProcessID, SignatureAlgorithm, SignatureReserveBytes: Integer): TPDFlibSignerResult;
    Function GetCertificateDER: AnsiString;
    Procedure SetPrivateKeyUI(AllowUI: Boolean);
    Procedure SetRSAPSSPadding(Enable: Boolean);
    Function CertificateKeyUsage: Integer;
    Function EstimateSignatureSize(Const Data, SubFilter: AnsiString;
      DigestAlgorithm: TPDFlibDigestAlgorithm;
      Const CommitmentTypeDER, SignaturePolicyDER, RevocationInfoDER: AnsiString): Integer;
    Function EstimateCertificateChainSize: Integer;
    Function SignData(Const Data, SubFilter: AnsiString; DigestAlgorithm: TPDFlibDigestAlgorithm;
      Const CommitmentTypeDER, SignaturePolicyDER, RevocationInfoDER: AnsiString): AnsiString;
  End;

Methods

OpenLoads a PFX or PKCS#12 file with its password; UseMachineKeyset selects the machine key set
OpenFromStoreLocates a certificate in a Windows system store by Subject simple display name and binds its context; the first certificate that carries a usable private key wins
EnumerateStoreFills the caller-supplied array with one TPDFlibCertificateInfo per store certificate and returns the count actually filled
OpenFromContextBinds an externally obtained PCCERT_CONTEXT; the caller keeps ownership and must keep the context valid until signing completes
OpenEd25519, OpenEd25519FromFileBind an Ed25519 certificate and seed from memory or from files
OpenCNGKey, OpenCNGKeyHandleBind a CNG-backed key by provider and key name, or by an existing key handle
OpenExternalDigestSignerSigns through the TPDFlibExternalDigestSignEvent callback instead of a local private key
GetCertificateDERThe bound certificate in DER form
SetPrivateKeyUIAllows or suppresses the CryptoAPI private-key prompt
SetRSAPSSPaddingSelects RSASSA-PSS padding for RSA detached signatures; legacy CryptoAPI keys keep PKCS#1 v1.5
CertificateKeyUsageThe X.509 key-usage bits packed as two bytes, or -1 when no context is bound
EstimateSignatureSize, EstimateCertificateChainSizeUpper bounds for the CMS output and the certificate chain
SignDataProduces the detached CMS signature for the data with the selected sub-filter and digest algorithm

Remarks

All open methods return TPDFlibSignerResult, so a failed identity binding can be reported precisely

The facade reaches the same identities through SetSignProcessPFXFromFile, SetSignProcessCertFromStore, SetSignProcessEd25519Identity and SetSignProcessCNGKey

See also

TPDFlibSignerResult, TPDFlibCertificateInfo, TPDFlibSigner, TPDFlibSignDoc, NewSignProcessFromFile