SetSignProcessCNGKey

安全和签名

描述

将命名 NCrypt 私钥及其 DER 编码 X.509 证书附加到 PDF 签名过程

密钥直接从请求的密钥存储提供程序中打开,从而支持由 TPM、硬件令牌、云 KSP 和其他仅 CNG 签名标识支持的密钥,无需导出私钥

语法

Delphi

Function TPDFlib.SetSignProcessCNGKey(SignProcessID: Integer; Const CertificateDER: AnsiString; Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): Integer;

ActiveX

Function PDFlib::SetSignProcessCNGKey(SignProcessID As Long, CertificateDER As Variant, ProviderName As String, KeyName As String, UseMachineKey As Long, AllowUI As Long) As Long

DLL

int DLSetSignProcessCNGKey(int InstanceID, int SignProcessID, const char* CertificateDER, int CertificateLength, const wchar_t* ProviderName, const wchar_t* KeyName, int UseMachineKey, int AllowUI);

参数

SignProcessID由 NewSignProcessFrom* 函数返回的值
CertificateDER与私钥对应的完整 DER 编码 RSA 或 ECDSA X.509 证书
ProviderNameWindows 密钥存储提供程序名称,或 Microsoft Software Key Storage Provider 的空字符串
KeyName提供程序可识别的持久密钥名称
UseMachineKey为 True 或非零时从计算机范围打开密钥
AllowUITrue 或非零值允许提供程序显示 PIN、同意或云审批用户界面

返回值

1身份配置已附加到该流程
0流程 ID、证书或密钥名称无效

备注

执行签名流程时打开密钥,私钥字节不会进入库内存

AllowUI 为 false 时,密钥打开和签名将应用 NCRYPT_SILENT_FLAG

生成的 CMS 签名会在接受前根据 CertificateDER 验证,因此会拒绝算法相同但密钥不匹配的签名

ActiveX 接受字节数组变体,DLL 使用显式证书长度以保留嵌入的零字节

另请参阅

SetSignProcessCNGKeyFromFile, SetSignProcessCNGKeyByHandle, SetSignProcessPrivateKeyUI