SetSignProcessCNGKey

安全與簽章

描述

將具名的 NCrypt 私密金鑰及其 DER 編碼 X.509 憑證接到 PDF 簽署程序

金鑰直接從要求的金鑰儲存提供者開啟,支援 TPM、硬體權杖、雲端 KSP 等僅限 CNG 的簽署身分,不必匯出私密金鑰

語法

Delphi

Function TPDFlib.SetSignProcessCNGKey(SignProcessID: Integer; Const CertificateDER: AnsiString; Const ProviderName, KeyName: WideString; UseMachineKey, AllowUI: Boolean): Integer;

ActiveX

Function PDFlib::SetSignProcessCNGKey(SignProcessID As Long, CertificateDER As Variant, ProviderName As String, KeyName As String, UseMachineKey As Long, AllowUI As Long) As Long

DLL

int DLSetSignProcessCNGKey(int InstanceID, int SignProcessID, const char* CertificateDER, int CertificateLength, const wchar_t* ProviderName, const wchar_t* KeyName, int UseMachineKey, int AllowUI);

參數

SignProcessIDNewSignProcessFrom* 函式傳回的值
CertificateDER與私密金鑰對應的完整 DER 編碼 RSA 或 ECDSA X.509 憑證
ProviderNameWindows 金鑰儲存提供者名稱;空字串表示 Microsoft Software Key Storage Provider
KeyName提供者能理解的持久鍵名稱
UseMachineKeytrue 或非零表示從機器範圍開啟金鑰
AllowUItrue 或非零表示允許提供者顯示 PIN、同意或雲端核准等使用者介面

傳回值

1身分設定已接到程序
0process id、憑證或金鑰名稱無效

備註

金鑰在簽署程序執行時才開啟,私鑰位元組不會進入程式庫記憶體

AllowUI 為 false 時,開啟金鑰與簽署都會套用 NCRYPT_SILENT_FLAG

產生的 CMS 簽章在接受前會對 CertificateDER 驗證,因此同演算法但金鑰不符會被拒絕

ActiveX 接受位元組陣列 variant;DLL 使用明確的憑證長度,內嵌的零位元組因此得以保留

另見

SetSignProcessCNGKeyFromFile, SetSignProcessCNGKeyByHandle, SetSignProcessPrivateKeyUI