SetSignProcessCNGKey
安全和签名
描述
将命名 NCrypt 私钥及其 DER 编码 X.509 证书附加到 PDF 签名过程
密钥直接从请求的密钥存储提供程序中打开,从而支持由 TPM、硬件令牌、云 KSP 和其他仅 CNG 签名标识支持的密钥,无需导出私钥
语法
Delphi
Function TPDFlib.SetSignProcessCNGKey(SignProcessID: Integer; Const CertificateDER: AnsiString; Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): Integer;
ActiveX
Function PDFlib::SetSignProcessCNGKey(SignProcessID As Long, CertificateDER As Variant, ProviderName As String, KeyName As String, UseMachineKey As Long, AllowUI As Long) As Long
DLL
int DLSetSignProcessCNGKey(int InstanceID, int SignProcessID, const char* CertificateDER, int CertificateLength, const wchar_t* ProviderName, const wchar_t* KeyName, int UseMachineKey, int AllowUI);
参数
| SignProcessID | 由 NewSignProcessFrom* 函数返回的值 |
|---|---|
| CertificateDER | 与私钥对应的完整 DER 编码 RSA 或 ECDSA X.509 证书 |
| ProviderName | Windows 密钥存储提供程序名称,或 Microsoft Software Key Storage Provider 的空字符串 |
| KeyName | 提供程序可识别的持久密钥名称 |
| UseMachineKey | 为 True 或非零时从计算机范围打开密钥 |
| AllowUI | True 或非零值允许提供程序显示 PIN、同意或云审批用户界面 |
返回值
| 1 | 身份配置已附加到该流程 |
|---|---|
| 0 | 流程 ID、证书或密钥名称无效 |
备注
执行签名流程时打开密钥,私钥字节不会进入库内存
AllowUI 为 false 时,密钥打开和签名将应用 NCRYPT_SILENT_FLAG
生成的 CMS 签名会在接受前根据 CertificateDER 验证,因此会拒绝算法相同但密钥不匹配的签名
ActiveX 接受字节数组变体,DLL 使用显式证书长度以保留嵌入的零字节
另请参阅
SetSignProcessCNGKeyFromFile, SetSignProcessCNGKeyByHandle, SetSignProcessPrivateKeyUI