SetSignProcessCNGKey
安全與簽章
描述
將具名的 NCrypt 私密金鑰及其 DER 編碼 X.509 憑證接到 PDF 簽署程序
金鑰直接從要求的金鑰儲存提供者開啟,支援 TPM、硬體權杖、雲端 KSP 等僅限 CNG 的簽署身分,不必匯出私密金鑰
語法
Delphi
Function TPDFlib.SetSignProcessCNGKey(SignProcessID: Integer; Const CertificateDER: AnsiString; Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): Integer;
ActiveX
Function PDFlib::SetSignProcessCNGKey(SignProcessID As Long, CertificateDER As Variant, ProviderName As String, KeyName As String, UseMachineKey As Long, AllowUI As Long) As Long
DLL
int DLSetSignProcessCNGKey(int InstanceID, int SignProcessID, const char* CertificateDER, int CertificateLength, const wchar_t* ProviderName, const wchar_t* KeyName, int UseMachineKey, int AllowUI);
參數
| SignProcessID | NewSignProcessFrom* 函式傳回的值 |
|---|---|
| CertificateDER | 與私密金鑰對應的完整 DER 編碼 RSA 或 ECDSA X.509 憑證 |
| ProviderName | Windows 金鑰儲存提供者名稱;空字串表示 Microsoft Software Key Storage Provider |
| KeyName | 提供者能理解的持久鍵名稱 |
| UseMachineKey | true 或非零表示從機器範圍開啟金鑰 |
| AllowUI | true 或非零表示允許提供者顯示 PIN、同意或雲端核准等使用者介面 |
傳回值
| 1 | 身分設定已接到程序 |
|---|---|
| 0 | process id、憑證或金鑰名稱無效 |
備註
金鑰在簽署程序執行時才開啟,私鑰位元組不會進入程式庫記憶體
AllowUI 為 false 時,開啟金鑰與簽署都會套用 NCRYPT_SILENT_FLAG
產生的 CMS 簽章在接受前會對 CertificateDER 驗證,因此同演算法但金鑰不符會被拒絕
ActiveX 接受位元組陣列 variant;DLL 使用明確的憑證長度,內嵌的零位元組因此得以保留
另見
SetSignProcessCNGKeyFromFile, SetSignProcessCNGKeyByHandle, SetSignProcessPrivateKeyUI