Struct secureblackbox::XMLSigner
Properties Methods Events Config Settings Errors
The XMLSigner struct provides a simple interface for digitally signing XML documents according to the XML-Signature Syntax and Processing specification.
Syntax
secureblackbox::XMLSigner
Remarks
XMLSigner implements the most basic XML-SIG signature standard. While this format is still quite widely used, it lacks important facilities that have been gaining popularity in recent years, such as strict chain validation, support for trust environments, and long-term signatures (also known as XAdES). If you are looking for XAdES support, please consider using the alternative XAdESSigner component.
To sign XML data with XMLSigner, you need to specify the data to be signed using the references property first, then select the signature type and signature method type (signature or MAC). References are individual pieces of the XML document that are covered by the signature. You can choose to sign the whole document or one or more individual elements.
Set the path to the file to be signed via the input_file (or input_bytes). Signed data will be saved in output_bytes, or the output_file if provided.
Finally, call the sign method to generate a signature and save the signed data. XMLSigner supports the two product-wide external signing approaches for
signing with remote private keys: use sign_external or sign_async_begin to do this as required.
XmlSigner.InputFile = "data.xml";
XmlSigner.OutputFile = "data-signed.xml";
XmlSigner.SigningCertificate = CertMgr.Certificate;
XmlSigner.Sign();
Object Lifetime
The new() method returns a mutable reference to a struct instance. The object itself is kept in the global list maintained by SecureBlackbox. Due to this, the XMLSigner struct cannot be disposed of automatically. Please, call the dispose(&mut self) method of XMLSigner when you have finished using the instance.
Property List
The following is the full list of the properties of the struct with short descriptions. Click on the links for further details.
| canonicalization_method | Specifies XML canonicalization method to use. |
| data_bytes | Use this property to pass the external data to struct in the byte array form. |
| data_file | A file containing the external data covered by a detached signature. |
| data_type | Specifies the external data type. |
| data_uri | Specifies a detached data resource URI. |
| encoding | Specifies XML encoding. |
| external_crypto_async_document_id | Specifies an optional document ID for SignAsyncBegin() and SignAsyncEnd() calls. |
| external_crypto_custom_params | Custom parameters to be passed to the signing service (uninterpreted). |
| external_crypto_data | Additional data to be included in the async state and mirrored back by the requestor. |
| external_crypto_external_hash_calculation | Specifies whether the message hash is to be calculated at the external endpoint. |
| external_crypto_hash_algorithm | Specifies the request's signature hash algorithm. |
| external_crypto_key_id | The ID of the pre-shared key used for DC request authentication. |
| external_crypto_key_secret | The pre-shared key used for DC request authentication. |
| external_crypto_method | Specifies the asynchronous signing method. |
| external_crypto_mode | Specifies the external cryptography mode. |
| external_crypto_public_key_algorithm | Provide the public key algorithm here if the certificate is not available on the pre-signing stage. |
| fips_mode | Reserved. |
| hash_algorithm | Specifies the hash algorithm to be used. |
| input_bytes | Use this property to pass the input to struct in byte array form. |
| input_file | Specifies the XML document to be signed. |
| output_bytes | Use this property to read the output the struct object has produced. |
| output_file | A file where the signed document is to be saved. |
| reference_count | The number of records in the Reference arrays. |
| reference_auto_generate_element_id | Specifies whether the identifier (ID) attribute for a referenced (target) element should be auto-generated during signing. |
| reference_canonicalization_method | Use this property to specify the canonicalization method for the transform of the reference. |
| reference_custom_element_id | Specifies a custom identifier (ID) attribute for a referenced (target) element that will be set on signing. |
| reference_digest_value | Use this property to get or set the value of the digest calculated over the referenced data. |
| reference_handle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
| reference_hash_algorithm | Specifies the hash algorithm to be used. |
| reference_has_uri | Specifies whether the URI is set (even when it is empty). |
| reference_id | A user-defined identifier (ID) attribute of this Reference element. |
| reference_inclusive_namespaces_prefix_list | Use this property to specify InclusiveNamespaces PrefixList for exclusive canonicalization transform of the reference. |
| reference_type | The Reference's type attribute as defined in XMLDSIG specification. |
| reference_target_data | Contains the referenced external data when the digest value is not explicitly specified. |
| reference_target_type | The reference's target type to use. |
| reference_target_xml_element | This property specifies the referenced XML element. |
| reference_uri | Use this property to get or set the URL which references the data. |
| reference_use_base64_transform | Specifies whether Base64 transform is included in transform chain. |
| reference_use_enveloped_signature_transform | Specifies whether enveloped signature transform is included in transform chain. |
| reference_use_xpath_filter2_transform | Specifies whether XPath Filter 2. |
| reference_use_xpath_transform | Specifies whether XPath transform is included in transform chain. |
| reference_validation_result | The outcome of the cryptographic reference validation. |
| reference_xpath_expression | Use this property to specify XPath expression for XPath transform of the reference. |
| reference_xpath_filter2_expressions | Use this property to specify XPointer expression(s) for XPath Filter 2. |
| reference_xpath_filter2_filters | Use this property to specify XPointer filter(s) for XPath Filter 2. |
| reference_xpath_filter2_prefix_list | Use this property to specify a prefix list for XPath Filter 2. |
| reference_xpath_prefix_list | Use this property to specify a prefix list for XPath transform of the reference. |
| signature_type | The signature type to employ when signing the document. |
| signing_cert_bytes | Returns the raw certificate data in DER format. |
| signing_cert_handle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
| signing_chain_count | The number of records in the SigningChain arrays. |
| signing_chain_bytes | Returns the raw certificate data in DER format. |
| signing_chain_handle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
| xml_element | Specifies the XML element where to save the signature data. |
Method List
The following is the full list of the methods of the struct with short descriptions. Click on the links for further details.
| add_data_reference | Creates a new XML reference to the specified data. |
| add_known_namespace | Adds known prefix and correspondent namespace URI. |
| add_reference | Creates a new XML reference to the specified XML element. |
| config | Sets or retrieves a configuration setting. |
| do_action | Performs an additional action. |
| extract_async_data | Extracts user data from the DC signing service response. |
| get_inner_xml | Get the inner XML content of the selected XML element. |
| get_outer_xml | Get the outer XML content of the selected XML element. |
| get_text_content | Get the text content of the selected XML element. |
| reset | Resets the struct settings. |
| set_inner_xml | Set the inner XML content of the selected XML element. |
| set_text_content | Set the text content of the selected XML element. |
| sign | Signs an XML document. |
| sign_async_begin | Initiates the asynchronous signing operation. |
| sign_async_end | Completes the asynchronous signing operation. |
| sign_external | Signs the document using an external signing facility. |
Event List
The following is the full list of the events fired by the struct with short descriptions. Click on the links for further details.
| on_error | Reports the details of signing errors. |
| on_external_sign | Handles remote or external signing initiated by the SignExternal method or other source. |
| on_format_element | Reports the XML element that is currently being processed. |
| on_format_text | Reports XML text that is currently being processed. |
| on_notification | This event notifies the application about an underlying control flow event. |
| on_resolve_reference | Asks the application to resolve a reference. |
Config Settings
The following is a list of config settings for the struct with short descriptions. Click on the links for further details.
| AddAllDataObjectsTimestamp | Whether to add all data objects timestamp during signing. |
| AsyncDocumentID | Specifies the document ID for SignAsyncEnd() call. |
| CachedCRLMaxAge | Specifies the maximum age of a cached CRL. |
| CachedCRLMaxAgeRatio | Specifies the maximum age of a cached CRL as a percentage of its remaining lifetime. |
| CachedCRLOverlapTime | Specifies the time period before a cached CRL's NextUpdate when it is considered stale and must be refreshed. |
| CachedOCSPResponseMaxAge | Specifies the maximum age of a cached OCSP response. |
| CachedOCSPResponseMaxAgeRatio | Specifies the maximum age of a cached OCSP response as a percentage of its remaining lifetime. |
| CachedOCSPResponseOverlapTime | Specifies the time period before a cached OCSP response's NextUpdate when it is considered stale and must be refreshed. |
| ChainCurrentCACert | Returns the current CA certificate. |
| ChainCurrentCert | Returns the certificate that is currently being validated. |
| ChainCurrentCRL | Returns the current CRL. |
| ChainCurrentCRLSize | Returns the size of the current CRL. |
| ChainCurrentOCSP | Returns the current OCSP response. |
| ChainCurrentOCSPSigner | Returns the signer of the current OCSP object. |
| ChainInterimDetails | Returns the current interim validation details. |
| ChainInterimResult | Returns the current interim validation result. |
| CheckValidityPeriodForTrusted | Whether to check validity period for trusted certificates. |
| ClaimedRolesXML | The XML content of the claimed roles. |
| ClaimedRoleText | The text of the claimed role. |
| CommitmentTypeIndicationAllSignedDataObjects[Index] | Specifies the CommitmentTypeIndication's AllSignedDataObjects. |
| CommitmentTypeIndicationCount | The number of the CommitmentTypeIndication elements. |
| CommitmentTypeIndicationIdentifier[Index] | Specifies the CommitmentTypeIndication's CommitmentTypeId's Identifier. |
| CommitmentTypeIndicationIdentifierDescription[Index] | Specifies the CommitmentTypeIndication's CommitmentTypeId's Description. |
| CommitmentTypeIndicationIdentifierDocumentationReferences[Index] | Specifies the CommitmentTypeIndication's CommitmentTypeId's DocumentationReferences. |
| CommitmentTypeIndicationIdentifierQualifier[Index] | Specifies the CommitmentTypeIndication's CommitmentTypeId's IdentifierQualifier. |
| CommitmentTypeIndicationObjectReference[Index] | Specifies the CommitmentTypeIndication's ObjectReference. |
| CommitmentTypeIndicationQualifiersXML[Index] | The XML content of the CommitmentTypeIndication's Qualifiers. |
| CustomTrustedLists | Specifies the custom TrustedLists. |
| CustomTSLs | Specifies the custom TrustedLists. |
| DataObjectFormatCount | The number of the DataObjectFormat elements. |
| DataObjectFormatDescription[Index] | Specifies the DataObjectFormat's Description. |
| DataObjectFormatEncoding[Index] | Specifies the DataObjectFormat's Encoding. |
| DataObjectFormatMimeType[Index] | Specifies the DataObjectFormat's MimeType. |
| DataObjectFormatObjectIdentifier[Index] | Specifies the DataObjectFormat's ObjectIdentifier's Identifier. |
| DataObjectFormatObjectIdentifierDescription[Index] | Specifies the DataObjectFormat's ObjectIdentifier's Description. |
| DataObjectFormatObjectIdentifierDocumentationReferences[Index] | Specifies the DataObjectFormat's ObjectIdentifier's DocumentationReferences. |
| DataObjectFormatObjectIdentifierQualifier[Index] | Specifies the DataObjectFormat's ObjectIdentifier's IdentifierQualifier. |
| DataObjectFormatObjectReference[Index] | Specifies the DataObjectFormat's ObjectReference. |
| DataType | Specifies the external data type. |
| DeltaCRLPreference | Specifies whether complete or delta CRLs are preferred. |
| DetachedResourceURI | Specifies a detached resource URI. |
| DislikeOpenEndedOCSPs | Tells the struct to discourage OCSP responses without an explicit NextUpdate parameter. |
| EnvelopingObjectEncoding | Specifies the enveloping object encoding. |
| EnvelopingObjectID | Specifies the enveloping object identifier. |
| EnvelopingObjectMimeType | Specifies the enveloping object MIME type. |
| EvaluateSystemTrust | Enables or disables usage of the platform's built-in trust validation facilities. |
| EvaluateSystemTrustForSelfSignedCertificates | Enables or disables usage of the platform's built-in trust validation facilities for self-signed certificates. |
| EvaluateSystemTrustForSSL | Enables or disables usage of the platform's built-in trust validation facilities for SSL/TLS. |
| ExclusiveCanonicalizationPrefix | Specifies the exclusive canonicalization prefix. |
| ForceCompleteChainValidation | Whether to check the CA certificates when the signing certificate is invalid. |
| ForceCompleteChainValidationForTrusted | Whether to continue with the full validation up to the root CA certificate for mid-level trust anchors. |
| GracePeriod | Specifies a grace period to apply during revocation information checks. |
| HMACKey | The key value for HMAC. |
| HMACOutputLength | Sets the length of the HMAC output. |
| HMACSigningUsed | Whether to use HMAC signing. |
| IDAttributeName | Specifies the custom name of ID attribute. |
| IDAttributeNamespaceURI | Specifies the custom namespace URI of ID attribute. |
| IgnoreChainLoops | Whether chain loops should be ignored. |
| IgnoreChainValidationErrors | Whether to ignore any certificate chain validation issues. |
| IgnoreOCSPNoCheckExtension | Whether the OCSP NoCheck extension should be ignored. |
| IgnoreSystemTrust | Whether trusted Windows Certificate Stores should be treated as trusted. |
| IgnoreTimestampFailure | Whether to ignore time-stamping failure during signing. |
| ImplicitlyTrustSelfSignedCertificates | Whether to trust self-signed certificates. |
| IncludeKey | Specifies whether to include the signing key to the signature. |
| IncludeKeyValue | Specifies whether the key value must be included to the signature. |
| IncludeKnownRevocationInfoToSignature | Whether to include custom revocation info to the signature. |
| InclusiveNamespacesPrefixList | Specifies the InclusiveNamespaces PrefixList. |
| InputType | Specifies the Input type. |
| InsertBeforeXMLElement | Defines the reference XML element for signature insertion. |
| KeyInfoCustomXML | The custom XML content for KeyInfo element. |
| KeyInfoDetails | Specifies the signing key info details to include to the signature. |
| KeyInfoID | Specifies the ID for KeyInfo element. |
| KeyInfoX509Chain | Specifies which certificates from SigningChain are included in the ds:KeyInfo element. |
| KeyName | Contains information about the key used for signing. |
| ManifestCount | TBD. |
| ManifestID[i] | TBD. |
| ManifestObjectIndex[i] | TBD. |
| ManifestXML[i] | TBD. |
| NormalizeNewLine | Controls whether newline combinations should be automatically normalized. |
| ObjectCount | TBD. |
| ObjectEncoding[i] | TBD. |
| ObjectID[i] | TBD. |
| ObjectMimeType[i] | TBD. |
| ObjectSignaturePropertiesCount | TBD. |
| ObjectSignaturePropertiesID[i] | TBD. |
| ObjectSignaturePropertiesObjectIndex[i] | TBD. |
| ObjectSignaturePropertiesXML[i] | TBD. |
| ObjectSignaturePropertyCount | TBD. |
| ObjectSignaturePropertyID[i] | TBD. |
| ObjectSignaturePropertyPropertiesIndex[i] | TBD. |
| ObjectSignaturePropertyTarget[i] | TBD. |
| ObjectSignaturePropertyXML[i] | TBD. |
| ObjectXML[i] | TBD. |
| PolicyDescription | signature policy description. |
| PolicyExplicitText | The explicit text of the user notice. |
| PolicyUNNumbers | The noticeNumbers part of the NoticeReference CAdES attribute. |
| PolicyUNOrganization | The organization part of the NoticeReference qualifier. |
| ProductionPlace | Identifies the place of the signature production. |
| PromoteLongOCSPResponses | Whether long OCSP responses are requested. |
| PSSUsed | Whether to use RSASSA-PSS algorithm. |
| QualifyingPropertiesID | Specifies the ID for QualifyingProperties element. |
| QualifyingPropertiesObjectID | Specifies the ID for object with QualifyingProperties element. |
| QualifyingPropertiesReferenceCount | The number of the QualifyingPropertiesReference elements. |
| QualifyingPropertiesReferenceID[Index] | Specifies the QualifyingPropertiesReference's ID. |
| QualifyingPropertiesReferenceURI[Index] | Specifies the QualifyingPropertiesReference's URI. |
| RefsTimestampType | Specifies references timestamp type to include to the signature. |
| RevocationCacheAgePolicy | Specifies a preset policy for cached CRL and OCSP response freshness settings. |
| SchemeParams | The algorithm scheme parameters to employ. |
| SignatureCompliance | Specifies the signature compliance mode. |
| SignatureID | Specifies the ID for Signature element. |
| SignaturePrefix | Specifies the signature prefix. |
| SignatureValueID | Specifies the ID for SignatureValue element. |
| SignedInfoID | Specifies the ID for SignedInfo element. |
| SignedPropertiesID | Specifies the ID for SignedProperties element. |
| SignedPropertiesReferenceCanonicalizationMethod | Specifies the canonicalization method used in SignedProperties reference. |
| SignedPropertiesReferenceHashAlgorithm | Specifies the hash algorithm used in SignedProperties reference. |
| SignedPropertiesReferenceID | Specifies the ID for Reference element that points to SignedProperties element. |
| SignedPropertiesReferenceInclusiveNamespacesPrefixList | Specifies the InclusiveNamespaces PrefixList used in SignedProperties reference. |
| SignedPropertiesReferenceIndex | Specifies the index of SignedProperties reference. |
| SignedSignaturePropertiesID | Specifies the ID for SignedSignatureProperties element. |
| SigningCertificatesChain | Specifies which certificates from SigningChain are included in the xades:SigningCertificate element. |
| SigningCertificatesHashAlgorithm | Specifies the hash algorithm used for SigningCertificates. |
| SigningTimeFormat | Specifies the date time format for the XAdES signing time. |
| SigningTimeIsUTC | Specifies whether the XAdES signing time is in UTC. |
| SigningTimeZoneOffset | Specifies the time zone offset for the XAdES signing time. |
| SigPolicyDescription | signature policy description. |
| SigPolicyExplicitText | The explicit text of the user notice. |
| SigPolicyHash | The EPES policy hash. |
| SigPolicyHashAlgorithm | The hash algorithm that was used to generate the EPES policy hash. |
| SigPolicyID | The EPES policy ID. |
| SigPolicyNoticeNumbers | The noticeNumbers part of the NoticeReference CAdES attribute. |
| SigPolicyNoticeOrganization | The organization part of the NoticeReference qualifier. |
| SigPolicyURI | The EPES policy URI. |
| StripWhitespace | Controls whether excessive whitespace characters should be stripped off when loading the document. |
| TempPath | Path for storing temporary files. |
| TimestampCanonicalizationMethod | Specifies canonicalization method used in timestamp. |
| TimestampResponse | A base16-encoded timestamp response received from a TSA. |
| TimestampValidationDataDetails | Specifies timestamp validation data details to include to the signature. |
| TLSChainValidationDetails | Contains the advanced details of the TLS server certificate validation. |
| TLSChainValidationResult | Contains the result of the TLS server certificate validation. |
| TLSClientAuthRequested | Indicates whether the TLS server requests client authentication. |
| TLSValidationLog | Contains the log of the TLS server certificate validation. |
| TolerateMinorChainIssues | Whether to tolerate minor chain issues. |
| TspAttemptCount | Specifies the number of timestamping request attempts. |
| TspHashAlgorithm | Sets a specific hash algorithm for use with the timestamping service. |
| TspReqPolicy | Sets a request policy ID to include in the timestamping request. |
| UseCustomTransformOrder | Enables custom ordering for the document transforms. |
| UseDefaultTrustedLists | Enables or disables the use of the default TrustedLists. |
| UseDefaultTSLs | Enables or disables the use of the default TrustedLists. |
| UseEnvStorages | Enables or disables use of the environment storages. |
| UseHMACSigning | Whether to use HMAC signing. |
| UseMicrosoftCTL | Enables or disables the automatic use of the Microsoft online certificate trust list. |
| UseMultipleX509DataNodes | Controls whether certificates are serialized in multiple ds:X509Data nodes under ds:KeyInfo. |
| UsePSS | Whether to use RSASSA-PSS algorithm. |
| UseSystemCertificates | Enables or disables the use of the system certificates. |
| UseValidationCache | Enables or disable the use of the product-wide certificate chain validation cache. |
| UseValidatorSettingsForTLSValidation | Whether to employ the primary chain validator setup for auxiliary TLS chain validations. |
| ValidationDataRefsDetails | Specifies validation data references details to include to the signature. |
| ValidationDataRefsHashAlgorithm | Specifies the hash algorithm used in validation data references. |
| ValidationDataValuesDetails | Specifies validation data values details to include to the signature. |
| WriteBOM | Specifies whether byte-order mark should be written when saving the document. |
| XAdESPrefix | Specifies the XAdES prefix. |
| XAdESv141Prefix | Specifies the XAdES v1.4.1 prefix. |
| XMLFormatting | Specifies the signature XML formatting. |
| XMLSerializationCanonicalizationMethod | Specifies the canonicalization method to use for serialization. |
| XMLSerializationMode | Specifies the serialization mode for the extracted part of XML document. |
| ASN1UseGlobalTagCache | Controls whether ASN.1 module should use a global object cache. |
| AssignSystemSmartCardPins | Specifies whether CSP-level PINs should be assigned to CNG keys. |
| CheckKeyIntegrityBeforeUse | Enables or disable private key integrity check before use. |
| CookieCaching | Specifies whether a cookie cache should be used for HTTP(S) transports. |
| Cookies | Gets or sets local cookies for the struct. |
| DefDeriveKeyIterations | Specifies the default key derivation algorithm iteration count. |
| DNSLocalSuffix | The suffix to assign for TLD names. |
| EnableClientSideSSLFFDHE | Enables or disables finite field DHE key exchange support in TLS clients. |
| EnableSSHMLKEM | Enables support for ML-KEM/hybrid key exchange algorithms in SSH client and server structs. |
| EnableTLSMLKEM | Enables support for ML-KEM and hybrid groups in TLS client and server structs. |
| GlobalCookies | Gets or sets global cookies for all the HTTP transports. |
| HardwareCryptoUsePolicy | The hardware crypto usage policy. |
| HttpUserAgent | Specifies the user agent name to be used by all HTTP clients. |
| HttpVersion | The HTTP version to use in any inner HTTP client structs created. |
| IgnoreExpiredMSCTLSigningCert | Whether to tolerate the expired Windows Update signing certificate. |
| ListDelimiter | The delimiter character for multi-element lists. |
| LogDestination | Specifies the debug log destination. |
| LogDetails | Specifies the debug log details to dump. |
| LogFile | Specifies the debug log filename. |
| LogFilters | Specifies the debug log filters. |
| LogFlushMode | Specifies the log flush mode. |
| LogLevel | Specifies the debug log level. |
| LogMaxEventCount | Specifies the maximum number of events to cache before further action is taken. |
| LogRotationMode | Specifies the log rotation mode. |
| MaxASN1BufferLength | Specifies the maximal allowed length for ASN.1 primitive tag data. |
| MaxASN1TreeDepth | Specifies the maximal depth for processed ASN.1 trees. |
| OCSPHashAlgorithm | Specifies the hash algorithm to be used to identify certificates in OCSP requests. |
| OldClientSideRSAFallback | Specifies whether the SSH client should use a SHA1 fallback. |
| PKICache | Specifies which PKI elements (certificates, CRLs, OCSP responses) should be cached. |
| PKICachePath | Specifies the file system path where cached PKI data is stored. |
| ProductVersion | Returns the version of the SecureBlackbox library. |
| ServerSSLDHKeyLength | Sets the size of the TLS DHE key exchange group. |
| StaticDNS | Specifies whether static DNS rules should be used. |
| StaticIPAddress[domain] | Gets or sets an IP address for the specified domain name. |
| StaticIPAddresses | Gets or sets all the static DNS rules. |
| Tag | Allows to store any custom data. |
| TLSSessionGroup | Specifies the group name of TLS sessions to be used for session resumption. |
| TLSSessionLifetime | Specifies lifetime in seconds of the cached TLS session. |
| TLSSessionPurgeInterval | Specifies how often the session cache should remove the expired TLS sessions. |
| UseCRLObjectCaching | Specifies whether reuse of loaded CRL objects is enabled. |
| UseInternalRandom | Switches between SecureBlackbox-own and platform PRNGs. |
| UseLegacyAdESValidation | Enables legacy AdES validation mode. |
| UseOCSPResponseObjectCaching | Specifies whether reuse of loaded OCSP response objects is enabled. |
| UseOwnDNSResolver | Specifies whether the client structs should use own DNS resolver. |
| UseSharedSystemStorages | Specifies whether the validation engine should use a global per-process copy of the system certificate stores. |
| UseSystemNativeSizeCalculation | An internal CryptoAPI access tweak. |
| UseSystemOAEPAndPSS | Enforces or disables the use of system-driven RSA OAEP and PSS computations. |
| UseSystemRandom | Enables or disables the use of the OS PRNG. |
| XMLRDNDescriptorName[OID] | Defines an OID mapping to descriptor names for the certificate's IssuerRDN or SubjectRDN. |
| XMLRDNDescriptorPriority[OID] | Specifies the priority of descriptor names associated with a specific OID. |
| XMLRDNDescriptorReverseOrder | Specifies whether to reverse the order of descriptors in RDN. |
| XMLRDNDescriptorSeparator | Specifies the separator used between descriptors in RDN. |
canonicalization_method property (XMLSigner Struct)
Specifies XML canonicalization method to use.
Syntax
fn canonicalization_method(&self ) -> Result<i32, SecureBlackboxError>
fn set_canonicalization_method(&self, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // None
1 // Canon
2 // CanonComment
3 // ExclCanon
4 // ExclCanonComment
5 // MinCanon
6 // Canon_v1_1
7 // CanonComment_v1_1
Default Value
1
Remarks
Use this property to specify the method for XML canonicalization of SignedInfo element. See XML-Signature Syntax and Processing specification for details.
Supported canonicalization methods:
| cxcmNone | 0 | |
| cxcmCanon | 1 | |
| cxcmCanonComment | 2 | |
| cxcmExclCanon | 3 | |
| cxcmExclCanonComment | 4 | |
| cxcmMinCanon | 5 | |
| cxcmCanon_v1_1 | 6 | |
| cxcmCanonComment_v1_1 | 7 |
Data Type
i32
data_bytes property (XMLSigner Struct)
Use this property to pass the external data to struct in the byte array form.
Syntax
fn data_bytes(&self ) -> Result<Vec<u8>, SecureBlackboxError>
fn set_data_bytes(&self, value : Vec<u8>) -> Option<SecureBlackboxError> fn set_data_bytes_ref(&self, value : &[u8]) -> Option<SecureBlackboxError>
Remarks
Assign a byte array containing the external data to be processed to this property.
Data Type
Vec
data_file property (XMLSigner Struct)
A file containing the external data covered by a detached signature.
Syntax
fn data_file(&self ) -> Result<String, SecureBlackboxError>
fn set_data_file(&self, value : &str) -> Option<SecureBlackboxError> fn set_data_file_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
In the case of a detached signature, use this property to provide the external data to the struct from a file. Alternatively, provide the data via data_stream.
Data Type
String
data_type property (XMLSigner Struct)
Specifies the external data type.
Syntax
fn data_type(&self ) -> Result<i32, SecureBlackboxError>
fn set_data_type(&self, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // XML
1 // Binary
2 // Base64
Default Value
0
Remarks
Use this property to specify the type of the external data (either data_file, data_stream or data_bytes properties) for struct.
Data Type
i32
data_uri property (XMLSigner Struct)
Specifies a detached data resource URI.
Syntax
fn data_uri(&self ) -> Result<String, SecureBlackboxError>
fn set_data_uri(&self, value : &str) -> Option<SecureBlackboxError> fn set_data_uri_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Specifies a URI used for data being signed, usually the data filename if stored along with a detached signature.
Data Type
String
encoding property (XMLSigner Struct)
Specifies XML encoding.
Syntax
fn encoding(&self ) -> Result<String, SecureBlackboxError>
fn set_encoding(&self, value : &str) -> Option<SecureBlackboxError> fn set_encoding_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify the encoding to apply to the XML documents.
Data Type
String
external_crypto_async_document_id property (XMLSigner Struct)
Specifies an optional document ID for SignAsyncBegin() and SignAsyncEnd() calls.
Syntax
fn external_crypto_async_document_id(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_async_document_id(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_async_document_id_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Specifies an optional document ID for SignAsyncBegin() and SignAsyncEnd() calls.
Use this property when working with multi-signature DCAuth requests and responses to uniquely identify documents signed within a larger batch. On the completion stage, this value helps the signing component identify the correct signature in the returned batch of responses.
If using batched requests, make sure to set this property to the same value on both the pre-signing (SignAsyncBegin) and completion (SignAsyncEnd) stages.
Data Type
String
external_crypto_custom_params property (XMLSigner Struct)
Custom parameters to be passed to the signing service (uninterpreted).
Syntax
fn external_crypto_custom_params(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_custom_params(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_custom_params_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Custom parameters to be passed to the signing service (uninterpreted).
Data Type
String
external_crypto_data property (XMLSigner Struct)
Additional data to be included in the async state and mirrored back by the requestor.
Syntax
fn external_crypto_data(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_data(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_data_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Additional data to be included in the async state and mirrored back by the requestor.
Data Type
String
external_crypto_external_hash_calculation property (XMLSigner Struct)
Specifies whether the message hash is to be calculated at the external endpoint.
Syntax
fn external_crypto_external_hash_calculation(&self ) -> Result<bool, SecureBlackboxError>
fn set_external_crypto_external_hash_calculation(&self, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether the message hash is to be calculated at the external endpoint. Please note that this mode is not supported by the DCAuth struct.
If set to true, the struct will pass a few kilobytes of to-be-signed data from the document to the OnExternalSign event. This only applies when SignExternal() is called.
Data Type
bool
external_crypto_hash_algorithm property (XMLSigner Struct)
Specifies the request's signature hash algorithm.
Syntax
fn external_crypto_hash_algorithm(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_hash_algorithm(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_hash_algorithm_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
"SHA256"
Remarks
Specifies the request's signature hash algorithm.
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_MD2 | MD2 | |
| SB_HASH_ALGORITHM_MD4 | MD4 | |
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_CRC32 | CRC32 | |
| SB_HASH_ALGORITHM_SSL3 | SSL3 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_POLY1305 | POLY1305 | |
| SB_HASH_ALGORITHM_SHA3_224 | SHA3_224 | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 | |
| SB_HASH_ALGORITHM_BLAKE2S_128 | BLAKE2S_128 | |
| SB_HASH_ALGORITHM_BLAKE2S_160 | BLAKE2S_160 | |
| SB_HASH_ALGORITHM_BLAKE2S_224 | BLAKE2S_224 | |
| SB_HASH_ALGORITHM_BLAKE2S_256 | BLAKE2S_256 | |
| SB_HASH_ALGORITHM_BLAKE2B_160 | BLAKE2B_160 | |
| SB_HASH_ALGORITHM_BLAKE2B_256 | BLAKE2B_256 | |
| SB_HASH_ALGORITHM_BLAKE2B_384 | BLAKE2B_384 | |
| SB_HASH_ALGORITHM_BLAKE2B_512 | BLAKE2B_512 | |
| SB_HASH_ALGORITHM_SHAKE_128 | SHAKE_128 | |
| SB_HASH_ALGORITHM_SHAKE_256 | SHAKE_256 | |
| SB_HASH_ALGORITHM_SHAKE_128_LEN | SHAKE_128_LEN | |
| SB_HASH_ALGORITHM_SHAKE_256_LEN | SHAKE_256_LEN |
Data Type
String
external_crypto_key_id property (XMLSigner Struct)
The ID of the pre-shared key used for DC request authentication.
Syntax
fn external_crypto_key_id(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_key_id(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_key_id_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
The ID of the pre-shared key used for DC request authentication.
Asynchronous DCAuth-driven communication requires that parties authenticate each other with a secret pre-shared cryptographic key. This provides an extra protection layer for the protocol and diminishes the risk of the private key becoming abused by foreign parties. Use this property to provide the pre-shared key identifier, and use external_crypto_key_secret to pass the key itself.
The same KeyID/KeySecret pair should be used on the DCAuth side for the signing requests to be accepted.
Note: The KeyID/KeySecret scheme is very similar to the AuthKey scheme used in various Cloud service providers to authenticate users.
Example:
signer.ExternalCrypto.KeyID = "MainSigningKey";
signer.ExternalCrypto.KeySecret = "abcdef0123456789";
Data Type
String
external_crypto_key_secret property (XMLSigner Struct)
The pre-shared key used for DC request authentication.
Syntax
fn external_crypto_key_secret(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_key_secret(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_key_secret_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
The pre-shared key used for DC request authentication. This key must be set and match the key used by the DCAuth counterpart for the scheme to work.
Read more about configuring authentication in the external_crypto_key_id topic.
Data Type
String
external_crypto_method property (XMLSigner Struct)
Specifies the asynchronous signing method.
Syntax
fn external_crypto_method(&self ) -> Result<i32, SecureBlackboxError>
fn set_external_crypto_method(&self, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // PKCS1
1 // PKCS7
Default Value
0
Remarks
Specifies the asynchronous signing method. This is typically defined by the DC server capabilities and setup.
Available options:
| asmdPKCS1 | 0 |
| asmdPKCS7 | 1 |
Data Type
i32
external_crypto_mode property (XMLSigner Struct)
Specifies the external cryptography mode.
Syntax
fn external_crypto_mode(&self ) -> Result<i32, SecureBlackboxError>
fn set_external_crypto_mode(&self, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // Default
1 // Disabled
2 // Generic
3 // DCAuth
4 // DCAuthJSON
Default Value
0
Remarks
Specifies the external cryptography mode.
Available options:
| ecmDefault | The default value (0) |
| ecmDisabled | Do not use DC or external signing (1) |
| ecmGeneric | Generic external signing with the OnExternalSign event (2) |
| ecmDCAuth | DCAuth signing (3) |
| ecmDCAuthJSON | DCAuth signing in JSON format (4) |
Data Type
i32
external_crypto_public_key_algorithm property (XMLSigner Struct)
Provide the public key algorithm here if the certificate is not available on the pre-signing stage.
Syntax
fn external_crypto_public_key_algorithm(&self ) -> Result<String, SecureBlackboxError>
fn set_external_crypto_public_key_algorithm(&self, value : &str) -> Option<SecureBlackboxError> fn set_external_crypto_public_key_algorithm_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Provide the public key algorithm here if the certificate is not available on the pre-signing stage.
| SB_CERT_ALGORITHM_ID_RSA_ENCRYPTION | rsaEncryption | |
| SB_CERT_ALGORITHM_MD2_RSA_ENCRYPTION | md2withRSAEncryption | |
| SB_CERT_ALGORITHM_MD5_RSA_ENCRYPTION | md5withRSAEncryption | |
| SB_CERT_ALGORITHM_SHA1_RSA_ENCRYPTION | sha1withRSAEncryption | |
| SB_CERT_ALGORITHM_ID_DSA | id-dsa | |
| SB_CERT_ALGORITHM_ID_DSA_SHA1 | id-dsa-with-sha1 | |
| SB_CERT_ALGORITHM_DH_PUBLIC | dhpublicnumber | |
| SB_CERT_ALGORITHM_SHA224_RSA_ENCRYPTION | sha224WithRSAEncryption | |
| SB_CERT_ALGORITHM_SHA256_RSA_ENCRYPTION | sha256WithRSAEncryption | |
| SB_CERT_ALGORITHM_SHA384_RSA_ENCRYPTION | sha384WithRSAEncryption | |
| SB_CERT_ALGORITHM_SHA512_RSA_ENCRYPTION | sha512WithRSAEncryption | |
| SB_CERT_ALGORITHM_ID_RSAPSS | id-RSASSA-PSS | |
| SB_CERT_ALGORITHM_ID_RSAOAEP | id-RSAES-OAEP | |
| SB_CERT_ALGORITHM_RSASIGNATURE_RIPEMD160 | ripemd160withRSA | |
| SB_CERT_ALGORITHM_ID_ELGAMAL | elGamal | |
| SB_CERT_ALGORITHM_SHA1_ECDSA | ecdsa-with-SHA1 | |
| SB_CERT_ALGORITHM_RECOMMENDED_ECDSA | ecdsa-recommended | |
| SB_CERT_ALGORITHM_SHA224_ECDSA | ecdsa-with-SHA224 | |
| SB_CERT_ALGORITHM_SHA256_ECDSA | ecdsa-with-SHA256 | |
| SB_CERT_ALGORITHM_SHA384_ECDSA | ecdsa-with-SHA384 | |
| SB_CERT_ALGORITHM_SHA512_ECDSA | ecdsa-with-SHA512 | |
| SB_CERT_ALGORITHM_EC | id-ecPublicKey | |
| SB_CERT_ALGORITHM_SPECIFIED_ECDSA | ecdsa-specified | |
| SB_CERT_ALGORITHM_GOST_R3410_1994 | id-GostR3410-94 | |
| SB_CERT_ALGORITHM_GOST_R3410_2001 | id-GostR3410-2001 | |
| SB_CERT_ALGORITHM_GOST_R3411_WITH_R3410_1994 | id-GostR3411-94-with-GostR3410-94 | |
| SB_CERT_ALGORITHM_GOST_R3411_WITH_R3410_2001 | id-GostR3411-94-with-GostR3410-2001 | |
| SB_CERT_ALGORITHM_SHA1_ECDSA_PLAIN | ecdsa-plain-SHA1 | |
| SB_CERT_ALGORITHM_SHA224_ECDSA_PLAIN | ecdsa-plain-SHA224 | |
| SB_CERT_ALGORITHM_SHA256_ECDSA_PLAIN | ecdsa-plain-SHA256 | |
| SB_CERT_ALGORITHM_SHA384_ECDSA_PLAIN | ecdsa-plain-SHA384 | |
| SB_CERT_ALGORITHM_SHA512_ECDSA_PLAIN | ecdsa-plain-SHA512 | |
| SB_CERT_ALGORITHM_RIPEMD160_ECDSA_PLAIN | ecdsa-plain-RIPEMD160 | |
| SB_CERT_ALGORITHM_WHIRLPOOL_RSA_ENCRYPTION | whirlpoolWithRSAEncryption | |
| SB_CERT_ALGORITHM_ID_DSA_SHA224 | id-dsa-with-sha224 | |
| SB_CERT_ALGORITHM_ID_DSA_SHA256 | id-dsa-with-sha256 | |
| SB_CERT_ALGORITHM_SHA3_224_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-sha3-224 | |
| SB_CERT_ALGORITHM_SHA3_256_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-sha3-256 | |
| SB_CERT_ALGORITHM_SHA3_384_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-sha3-384 | |
| SB_CERT_ALGORITHM_SHA3_512_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-sha3-512 | |
| SB_CERT_ALGORITHM_SHA3_224_ECDSA | id-ecdsa-with-sha3-224 | |
| SB_CERT_ALGORITHM_SHA3_256_ECDSA | id-ecdsa-with-sha3-256 | |
| SB_CERT_ALGORITHM_SHA3_384_ECDSA | id-ecdsa-with-sha3-384 | |
| SB_CERT_ALGORITHM_SHA3_512_ECDSA | id-ecdsa-with-sha3-512 | |
| SB_CERT_ALGORITHM_SHA3_224_ECDSA_PLAIN | id-ecdsa-plain-with-sha3-224 | |
| SB_CERT_ALGORITHM_SHA3_256_ECDSA_PLAIN | id-ecdsa-plain-with-sha3-256 | |
| SB_CERT_ALGORITHM_SHA3_384_ECDSA_PLAIN | id-ecdsa-plain-with-sha3-384 | |
| SB_CERT_ALGORITHM_SHA3_512_ECDSA_PLAIN | id-ecdsa-plain-with-sha3-512 | |
| SB_CERT_ALGORITHM_ID_DSA_SHA3_224 | id-dsa-with-sha3-224 | |
| SB_CERT_ALGORITHM_ID_DSA_SHA3_256 | id-dsa-with-sha3-256 | |
| SB_CERT_ALGORITHM_BLAKE2S_128_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2s128 | |
| SB_CERT_ALGORITHM_BLAKE2S_160_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2s160 | |
| SB_CERT_ALGORITHM_BLAKE2S_224_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2s224 | |
| SB_CERT_ALGORITHM_BLAKE2S_256_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2s256 | |
| SB_CERT_ALGORITHM_BLAKE2B_160_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2b160 | |
| SB_CERT_ALGORITHM_BLAKE2B_256_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2b256 | |
| SB_CERT_ALGORITHM_BLAKE2B_384_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2b384 | |
| SB_CERT_ALGORITHM_BLAKE2B_512_RSA_ENCRYPTION | id-rsassa-pkcs1-v1_5-with-blake2b512 | |
| SB_CERT_ALGORITHM_BLAKE2S_128_ECDSA | id-ecdsa-with-blake2s128 | |
| SB_CERT_ALGORITHM_BLAKE2S_160_ECDSA | id-ecdsa-with-blake2s160 | |
| SB_CERT_ALGORITHM_BLAKE2S_224_ECDSA | id-ecdsa-with-blake2s224 | |
| SB_CERT_ALGORITHM_BLAKE2S_256_ECDSA | id-ecdsa-with-blake2s256 | |
| SB_CERT_ALGORITHM_BLAKE2B_160_ECDSA | id-ecdsa-with-blake2b160 | |
| SB_CERT_ALGORITHM_BLAKE2B_256_ECDSA | id-ecdsa-with-blake2b256 | |
| SB_CERT_ALGORITHM_BLAKE2B_384_ECDSA | id-ecdsa-with-blake2b384 | |
| SB_CERT_ALGORITHM_BLAKE2B_512_ECDSA | id-ecdsa-with-blake2b512 | |
| SB_CERT_ALGORITHM_BLAKE2S_128_ECDSA_PLAIN | id-ecdsa-plain-with-blake2s128 | |
| SB_CERT_ALGORITHM_BLAKE2S_160_ECDSA_PLAIN | id-ecdsa-plain-with-blake2s160 | |
| SB_CERT_ALGORITHM_BLAKE2S_224_ECDSA_PLAIN | id-ecdsa-plain-with-blake2s224 | |
| SB_CERT_ALGORITHM_BLAKE2S_256_ECDSA_PLAIN | id-ecdsa-plain-with-blake2s256 | |
| SB_CERT_ALGORITHM_BLAKE2B_160_ECDSA_PLAIN | id-ecdsa-plain-with-blake2b160 | |
| SB_CERT_ALGORITHM_BLAKE2B_256_ECDSA_PLAIN | id-ecdsa-plain-with-blake2b256 | |
| SB_CERT_ALGORITHM_BLAKE2B_384_ECDSA_PLAIN | id-ecdsa-plain-with-blake2b384 | |
| SB_CERT_ALGORITHM_BLAKE2B_512_ECDSA_PLAIN | id-ecdsa-plain-with-blake2b512 | |
| SB_CERT_ALGORITHM_ID_DSA_BLAKE2S_224 | id-dsa-with-blake2s224 | |
| SB_CERT_ALGORITHM_ID_DSA_BLAKE2S_256 | id-dsa-with-blake2s256 | |
| SB_CERT_ALGORITHM_EDDSA_ED25519 | id-Ed25519 | |
| SB_CERT_ALGORITHM_EDDSA_ED448 | id-Ed448 | |
| SB_CERT_ALGORITHM_EDDSA_ED25519_PH | id-Ed25519ph | |
| SB_CERT_ALGORITHM_EDDSA_ED448_PH | id-Ed448ph | |
| SB_CERT_ALGORITHM_EDDSA | id-EdDSA | |
| SB_CERT_ALGORITHM_EDDSA_SIGNATURE | id-EdDSA-sig | |
| SB_CERT_ALGORITHM_MLDSA_44 | id-ml-dsa-44 | |
| SB_CERT_ALGORITHM_MLDSA_65 | id-ml-dsa-65 | |
| SB_CERT_ALGORITHM_MLDSA_87 | id-ml-dsa-87 | |
| SB_CERT_ALGORITHM_HASH_MLDSA_44_SHA512 | id-hash-ml-dsa-44-with-sha512 | |
| SB_CERT_ALGORITHM_HASH_MLDSA_65_SHA512 | id-hash-ml-dsa-65-with-sha512 | |
| SB_CERT_ALGORITHM_HASH_MLDSA_87_SHA512 | id-hash-ml-dsa-87-with-sha512 | |
| SB_CERT_ALGORITHM_MLKEM_512 | id-ml-kem-512 | |
| SB_CERT_ALGORITHM_MLKEM_768 | id-ml-kem-768 | |
| SB_CERT_ALGORITHM_MLKEM_1024 | id-ml-kem-1024 |
Data Type
String
fips_mode property (XMLSigner Struct)
Reserved.
Syntax
fn fips_mode(&self ) -> Result<bool, SecureBlackboxError>
fn set_fips_mode(&self, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
This property is reserved for future use.
Data Type
bool
hash_algorithm property (XMLSigner Struct)
Specifies the hash algorithm to be used.
Syntax
fn hash_algorithm(&self ) -> Result<String, SecureBlackboxError>
fn set_hash_algorithm(&self, value : &str) -> Option<SecureBlackboxError> fn set_hash_algorithm_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
"SHA256"
Remarks
Use this property to set the hash algorithm for signature calculation.
Supported values:
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 |
Data Type
String
input_bytes property (XMLSigner Struct)
Use this property to pass the input to struct in byte array form.
Syntax
fn input_bytes(&self ) -> Result<Vec<u8>, SecureBlackboxError>
fn set_input_bytes(&self, value : Vec<u8>) -> Option<SecureBlackboxError> fn set_input_bytes_ref(&self, value : &[u8]) -> Option<SecureBlackboxError>
Remarks
Assign a byte array containing the data to be processed to this property.
Data Type
Vec
input_file property (XMLSigner Struct)
Specifies the XML document to be signed.
Syntax
fn input_file(&self ) -> Result<String, SecureBlackboxError>
fn set_input_file(&self, value : &str) -> Option<SecureBlackboxError> fn set_input_file_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Provide a path to the XML file to be signed.
Data Type
String
output_bytes property (XMLSigner Struct)
Use this property to read the output the struct object has produced.
Syntax
fn output_bytes(&self ) -> Result<Vec<u8>, SecureBlackboxError>
Remarks
Read the contents of this property after the operation has completed to read the produced output. This property will only be set if the output_file and output_stream properties had not been assigned.
This property is read-only.
Data Type
Vec
output_file property (XMLSigner Struct)
A file where the signed document is to be saved.
Syntax
fn output_file(&self ) -> Result<String, SecureBlackboxError>
fn set_output_file(&self, value : &str) -> Option<SecureBlackboxError> fn set_output_file_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Provide a path to the file where the signed document is to be saved.
Data Type
String
reference_count property (XMLSigner Struct)
The number of records in the Reference arrays.
Syntax
fn reference_count(&self ) -> Result<i32, SecureBlackboxError>
fn set_reference_count(&self, value : i32) -> Option<SecureBlackboxError>
Default Value
0
Remarks
This property controls the size of the following arrays:
- reference_auto_generate_element_id
- reference_canonicalization_method
- reference_custom_element_id
- reference_digest_value
- reference_handle
- reference_hash_algorithm
- reference_has_uri
- reference_id
- reference_inclusive_namespaces_prefix_list
- reference_target_data
- reference_target_type
- reference_target_xml_element
- reference_type
- reference_uri
- reference_use_base64_transform
- reference_use_enveloped_signature_transform
- reference_use_xpath_filter2_transform
- reference_use_xpath_transform
- reference_validation_result
- reference_xpath_expression
- reference_xpath_filter2_expressions
- reference_xpath_filter2_filters
- reference_xpath_filter2_prefix_list
- reference_xpath_prefix_list
Data Type
i32
reference_auto_generate_element_id property (XMLSigner Struct)
Specifies whether the identifier (ID) attribute for a referenced (target) element should be auto-generated during signing.
Syntax
fn reference_auto_generate_element_id(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_auto_generate_element_id(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether the identifier (ID) attribute for a referenced (target) element should be auto-generated during signing. Used when the referenced element doesn't have an ID and CustomElementId and URI properties are empty.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_canonicalization_method property (XMLSigner Struct)
Use this property to specify the canonicalization method for the transform of the reference.
Syntax
fn reference_canonicalization_method(&self , ReferenceIndex : i32) -> Result<i32, SecureBlackboxError>
fn set_reference_canonicalization_method(&self, ReferenceIndex : i32, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // None
1 // Canon
2 // CanonComment
3 // ExclCanon
4 // ExclCanonComment
5 // MinCanon
6 // Canon_v1_1
7 // CanonComment_v1_1
Default Value
0
Remarks
Use this property to specify the canonicalization method for the transform of the reference. Use cxcmNone value to not to include canonicalization transform in transform chain. See XML-Signature Syntax and Processing specification for details.
| cxcmNone | 0 | |
| cxcmCanon | 1 | |
| cxcmCanonComment | 2 | |
| cxcmExclCanon | 3 | |
| cxcmExclCanonComment | 4 | |
| cxcmMinCanon | 5 | |
| cxcmCanon_v1_1 | 6 | |
| cxcmCanonComment_v1_1 | 7 |
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
i32
reference_custom_element_id property (XMLSigner Struct)
Specifies a custom identifier (ID) attribute for a referenced (target) element that will be set on signing.
Syntax
fn reference_custom_element_id(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_custom_element_id(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_custom_element_id_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Specifies a custom identifier (ID) attribute for a referenced (target) element that will be set on signing. Used when the referenced element doesn't have an ID and URI property is empty.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_digest_value property (XMLSigner Struct)
Use this property to get or set the value of the digest calculated over the referenced data.
Syntax
fn reference_digest_value(&self , ReferenceIndex : i32) -> Result<Vec<u8>, SecureBlackboxError>
fn set_reference_digest_value(&self, ReferenceIndex : i32, value : Vec<u8>) -> Option<SecureBlackboxError> fn set_reference_digest_value_ref(&self, ReferenceIndex : i32, value : &[u8]) -> Option<SecureBlackboxError>
Remarks
Use this property to get or set the value of the digest calculated over the referenced data.
This property is optional and should be set only if you don't provide the actual data via TargetData or URI. If the data is set, then you don't need to set DigestValue since it will be calculated automatically.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
Vec
reference_handle property (XMLSigner Struct)
Allows to get or set a 'handle', a unique identifier of the underlying property object.
Syntax
fn reference_handle(&self , ReferenceIndex : i32) -> Result<i64, SecureBlackboxError>
fn set_reference_handle(&self, ReferenceIndex : i32, value : i64) -> Option<SecureBlackboxError>
Default Value
0
Remarks
Allows to get or set a 'handle', a unique identifier of the underlying property object. Use this property to assign objects of the same type in a quicker manner, without copying them fieldwise.
When you pass a handle of one object to another, the source object is copied to the destination rather than assigned. It is safe to get rid of the original object
after such operation.
pdfSigner.setSigningCertHandle(certMgr.getCertHandle());
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
i64
reference_hash_algorithm property (XMLSigner Struct)
Specifies the hash algorithm to be used.
Syntax
fn reference_hash_algorithm(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_hash_algorithm(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_hash_algorithm_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
"SHA256"
Remarks
Specifies the hash algorithm to be used.
Supported values:
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 |
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_has_uri property (XMLSigner Struct)
Specifies whether the URI is set (even when it is empty).
Syntax
fn reference_has_uri(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_has_uri(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
true
Remarks
Specifies whether the URI is set (even when it is empty).
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_id property (XMLSigner Struct)
A user-defined identifier (ID) attribute of this Reference element.
Syntax
fn reference_id(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_id(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_id_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
A user-defined identifier (ID) attribute of this Reference element.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_inclusive_namespaces_prefix_list property (XMLSigner Struct)
Use this property to specify InclusiveNamespaces PrefixList for exclusive canonicalization transform of the reference.
Syntax
fn reference_inclusive_namespaces_prefix_list(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_inclusive_namespaces_prefix_list(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_inclusive_namespaces_prefix_list_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify InclusiveNamespaces PrefixList for exclusive canonicalization transform of the reference. See XML-Signature Syntax and Processing specification for details.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_type property (XMLSigner Struct)
The Reference's type attribute as defined in XMLDSIG specification.
Syntax
fn reference_type(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_type(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_type_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
The Reference's type attribute as defined in XMLDSIG specification.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_target_data property (XMLSigner Struct)
Contains the referenced external data when the digest value is not explicitly specified.
Syntax
fn reference_target_data(&self , ReferenceIndex : i32) -> Result<Vec<u8>, SecureBlackboxError>
fn set_reference_target_data(&self, ReferenceIndex : i32, value : Vec<u8>) -> Option<SecureBlackboxError> fn set_reference_target_data_ref(&self, ReferenceIndex : i32, value : &[u8]) -> Option<SecureBlackboxError>
Remarks
Contains the referenced external data when the digest value is not explicitly specified.
This property is optional and should only be set if you reference the external data via URI, and you don't provide the digest value explicitly via DigestValue.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
Vec
reference_target_type property (XMLSigner Struct)
The reference's target type to use.
Syntax
fn reference_target_type(&self , ReferenceIndex : i32) -> Result<i32, SecureBlackboxError>
fn set_reference_target_type(&self, ReferenceIndex : i32, value : i32) -> Option<SecureBlackboxError>
Possible Values
0 // Auto
1 // XMLElement
2 // Data
3 // URI
Default Value
0
Remarks
The reference's target type to use.
Use this property to specify the reference's target type to use when forming the signature.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
i32
reference_target_xml_element property (XMLSigner Struct)
This property specifies the referenced XML element.
Syntax
fn reference_target_xml_element(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_target_xml_element(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_target_xml_element_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
This property specifies the referenced XML element. Used when the URI property is not set. In this case, the URI value is generated based on the ID of the referenced (target) XML element. If the URI property is set, this property is ignored until the ResolveReference event.
Supported values are:
| "" | an empty string indicates the Document element. |
| "#id" | indicates an XML element with specified Id. |
| XPointer expression | indicates an XML element selected using XPointer expression. Use the add_known_namespace method to specify Prefixes and NamespaceURIs
For example: "/root/data[1]" - indicates the second "data" element under the document element with a name "root" "//ns1:data" - indicates a data element. "ns1" prefix should be defined via add_known_namespace method. |
| Node name | indicates an XML element selected using its NodeName.
For example: "data" - indicates an XML element with node name "data". |
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_uri property (XMLSigner Struct)
Use this property to get or set the URL which references the data.
Syntax
fn reference_uri(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_uri(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_uri_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to get or set the URL which references the data. If the data is external, the application must set either TargetData or DigestValue. If TargetData is set, the digest is calculated automatically unless it is explicitly set by the application via DigestValue.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_use_base64_transform property (XMLSigner Struct)
Specifies whether Base64 transform is included in transform chain.
Syntax
fn reference_use_base64_transform(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_use_base64_transform(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether Base64 transform is included in transform chain.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_use_enveloped_signature_transform property (XMLSigner Struct)
Specifies whether enveloped signature transform is included in transform chain.
Syntax
fn reference_use_enveloped_signature_transform(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_use_enveloped_signature_transform(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether enveloped signature transform is included in transform chain.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_use_xpath_filter2_transform property (XMLSigner Struct)
Specifies whether XPath Filter 2.
Syntax
fn reference_use_xpath_filter2_transform(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_use_xpath_filter2_transform(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether XPath Filter 2.0 transform is included in transform chain.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_use_xpath_transform property (XMLSigner Struct)
Specifies whether XPath transform is included in transform chain.
Syntax
fn reference_use_xpath_transform(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
fn set_reference_use_xpath_transform(&self, ReferenceIndex : i32, value : bool) -> Option<SecureBlackboxError>
Default Value
false
Remarks
Specifies whether XPath transform is included in transform chain.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
bool
reference_validation_result property (XMLSigner Struct)
The outcome of the cryptographic reference validation.
Syntax
fn reference_validation_result(&self , ReferenceIndex : i32) -> Result<bool, SecureBlackboxError>
Default Value
false
Remarks
The outcome of the cryptographic reference validation.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
This property is read-only.
Data Type
bool
reference_xpath_expression property (XMLSigner Struct)
Use this property to specify XPath expression for XPath transform of the reference.
Syntax
fn reference_xpath_expression(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_xpath_expression(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_xpath_expression_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify XPath expression for XPath transform of the reference.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_xpath_filter2_expressions property (XMLSigner Struct)
Use this property to specify XPointer expression(s) for XPath Filter 2.
Syntax
fn reference_xpath_filter2_expressions(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_xpath_filter2_expressions(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_xpath_filter2_expressions_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify XPointer expression(s) for XPath Filter 2.0 transform of the reference.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_xpath_filter2_filters property (XMLSigner Struct)
Use this property to specify XPointer filter(s) for XPath Filter 2.
Syntax
fn reference_xpath_filter2_filters(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_xpath_filter2_filters(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_xpath_filter2_filters_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify XPointer filter(s) for XPath Filter 2.0 transform of the reference. The prefix list is comma-separated.
Supported values:
| "intersect" | Intersect filter computes the intersection of the selected subtrees with the filter node-set. |
| "subtract" | Subtract filter computes the subtraction of the selected subtrees with the filter node-set. |
| "union" | Union filter computes the union of the selected subtrees with the filter node-set. |
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_xpath_filter2_prefix_list property (XMLSigner Struct)
Use this property to specify a prefix list for XPath Filter 2.
Syntax
fn reference_xpath_filter2_prefix_list(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_xpath_filter2_prefix_list(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_xpath_filter2_prefix_list_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify a prefix list for XPath Filter 2.0 transform of the reference. The prefix list is space-separated. Namespace URIs that are used are taken from XPathNamespaces property.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
reference_xpath_prefix_list property (XMLSigner Struct)
Use this property to specify a prefix list for XPath transform of the reference.
Syntax
fn reference_xpath_prefix_list(&self , ReferenceIndex : i32) -> Result<String, SecureBlackboxError>
fn set_reference_xpath_prefix_list(&self, ReferenceIndex : i32, value : &str) -> Option<SecureBlackboxError> fn set_reference_xpath_prefix_list_ref(&self, ReferenceIndex : i32, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
Use this property to specify a prefix list for XPath transform of the reference. The prefix list is space-separated. Namespace URIs that are used are taken from XPathNamespaces property.
The ReferenceIndex parameter specifies the index of the item in the array. The size of the array is controlled by the ReferenceCount property.
Data Type
String
signature_type property (XMLSigner Struct)
The signature type to employ when signing the document.
Syntax
fn signature_type(&self ) -> Result<i32, SecureBlackboxError>
fn set_signature_type(&self, value : i32) -> Option<SecureBlackboxError>
Possible Values
1 // Detached
2 // Enveloping
4 // Enveloped
Default Value
4
Remarks
This property specifies the signature type to be used when signing the document.
Supported values:
| cxstDetached | 1 | Specifies whether a detached signature should be produced. I.e., a signature which is kept separately from the signed document. |
| cxstEnveloping | 2 | Specifies whether an enveloping signature should be produced. |
| cxstEnveloped | 4 | Specifies whether an enveloped signature should be produced. |
Data Type
i32
signing_cert_bytes property (XMLSigner Struct)
Returns the raw certificate data in DER format.
Syntax
fn signing_cert_bytes(&self ) -> Result<Vec<u8>, SecureBlackboxError>
Remarks
Returns the raw certificate data in DER format.
This property is read-only.
Data Type
Vec
signing_cert_handle property (XMLSigner Struct)
Allows to get or set a 'handle', a unique identifier of the underlying property object.
Syntax
fn signing_cert_handle(&self ) -> Result<i64, SecureBlackboxError>
fn set_signing_cert_handle(&self, value : i64) -> Option<SecureBlackboxError>
Default Value
0
Remarks
Allows to get or set a 'handle', a unique identifier of the underlying property object. Use this property to assign objects of the same type in a quicker manner, without copying them fieldwise.
When you pass a handle of one object to another, the source object is copied to the destination rather than assigned. It is safe to get rid of the original object
after such operation.
pdfSigner.setSigningCertHandle(certMgr.getCertHandle());
Data Type
i64
signing_chain_count property (XMLSigner Struct)
The number of records in the SigningChain arrays.
Syntax
fn signing_chain_count(&self ) -> Result<i32, SecureBlackboxError>
fn set_signing_chain_count(&self, value : i32) -> Option<SecureBlackboxError>
Default Value
0
Remarks
This property controls the size of the following arrays:
The array indices start at 0 and end at signing_chain_count - 1.Data Type
i32
signing_chain_bytes property (XMLSigner Struct)
Returns the raw certificate data in DER format.
Syntax
fn signing_chain_bytes(&self , SigningChainIndex : i32) -> Result<Vec<u8>, SecureBlackboxError>
Remarks
Returns the raw certificate data in DER format.
The SigningChainIndex parameter specifies the index of the item in the array. The size of the array is controlled by the SigningChainCount property.
This property is read-only.
Data Type
Vec
signing_chain_handle property (XMLSigner Struct)
Allows to get or set a 'handle', a unique identifier of the underlying property object.
Syntax
fn signing_chain_handle(&self , SigningChainIndex : i32) -> Result<i64, SecureBlackboxError>
fn set_signing_chain_handle(&self, SigningChainIndex : i32, value : i64) -> Option<SecureBlackboxError>
Default Value
0
Remarks
Allows to get or set a 'handle', a unique identifier of the underlying property object. Use this property to assign objects of the same type in a quicker manner, without copying them fieldwise.
When you pass a handle of one object to another, the source object is copied to the destination rather than assigned. It is safe to get rid of the original object
after such operation.
pdfSigner.setSigningCertHandle(certMgr.getCertHandle());
The SigningChainIndex parameter specifies the index of the item in the array. The size of the array is controlled by the SigningChainCount property.
Data Type
i64
xml_element property (XMLSigner Struct)
Specifies the XML element where to save the signature data.
Syntax
fn xml_element(&self ) -> Result<String, SecureBlackboxError>
fn set_xml_element(&self, value : &str) -> Option<SecureBlackboxError> fn set_xml_element_ref(&self, value : &String) -> Option<SecureBlackboxError>
Default Value
""
Remarks
This property specifies the XML element where to save the electronic signature.
Supported values are:
| "" | an empty string indicates the Document element |
| "#id" | indicates an XML element with specified Id |
| XPath expression | indicates an XML element selected using XPath expression. Use add_known_namespace method to specify Prefixes and NamespaceURIs
For example: "/root/data[1]" - indicates the second "data" element under the document element with a name "root" "//ns1:data" - indicates a data element. "ns1" prefix should be defined via add_known_namespace method. |
| Node name | indicates an XML element selected using its NodeName.
For example: "data" - indicates an XML element with node name "data". |
Data Type
String
add_data_reference method (XMLSigner Struct)
Creates a new XML reference to the specified data.
Syntax
fn add_data_reference(&self, data_uri : &str, data : &[u8]) -> Result<i32, SecureBlackboxError>
Remarks
Use this method to add a reference to the custom data. Pass the reference's URI via DataURI parameter.
This method uses hash_algorithm property to specify the hash algorithm of the reference.
The method returns the index of the new reference entry in the references collection.
add_known_namespace method (XMLSigner Struct)
Adds known prefix and correspondent namespace URI.
Syntax
fn add_known_namespace(&self, prefix : &str, uri : &str) -> Result<(), SecureBlackboxError>
Remarks
Use this method to add a known prefix and namespace URI that are used in XPath expression within XMLElement/XMLNode property, and within TargetXMLElement and XPathPrefixList properties of the references.
add_reference method (XMLSigner Struct)
Creates a new XML reference to the specified XML element.
Syntax
fn add_reference(&self, target_xml_element : &str, custom_id : &str, auto_generate_id : bool) -> Result<i32, SecureBlackboxError>
Remarks
Use this method to add a reference to a particular XML element.
The reference's URI is set basing on the ID of the XML element. If the XML element doesn't have an ID then a CustomId value will be used. If CustomId is empty and AutoGenerateId is set, the ID will be generated automatically. An exception will be thrown otherwise.
This method uses canonicalization_method and hash_algorithm properties to specify the canonicalization method and hash algorithm of the reference.
The method returns the index of the new reference entry in the references collection.
config method (XMLSigner Struct)
Sets or retrieves a configuration setting.
Syntax
fn config(&self, configuration_string : &str) -> Result<String, SecureBlackboxError>
Remarks
config is a generic method available in every struct. It is used to set and retrieve configuration settings for the struct.
These settings are similar in functionality to properties, but they are rarely used. In order to avoid "polluting" the property namespace of the struct, access to these internal properties is provided through the config method.
To set a configuration setting named PROPERTY, you must call Config("PROPERTY=VALUE"), where VALUE is the value of the setting expressed as a string. For boolean values, use the strings "True", "False", "0", "1", "Yes", or "No" (case does not matter).
To read (query) the value of a configuration setting, you must call Config("PROPERTY"). The value will be returned as a string.
do_action method (XMLSigner Struct)
Performs an additional action.
Syntax
fn do_action(&self, action_id : &str, action_params : &str) -> Result<String, SecureBlackboxError>
Remarks
do_action is a generic method available in every struct. It is used to perform an additional action introduced after the product major release. The list of actions is not fixed, and may be flexibly extended over time.
The unique identifier (case insensitive) of the action is provided in the ActionID parameter.
ActionParams contains the value of a single parameter, or a list of multiple parameters for the action in the form of PARAM1=VALUE1;PARAM2=VALUE2;....
Common ActionIDs:
| Action | Parameters | Returned value | Description |
| ResetTrustedListCache | none | none | Clears the cached list of trusted lists. |
| ResetCertificateCache | none | none | Clears the cached certificates. |
| ResetCRLCache | none | none | Clears the cached CRLs. |
| ResetOCSPResponseCache | none | none | Clears the cached OCSP responses. |
extract_async_data method (XMLSigner Struct)
Extracts user data from the DC signing service response.
Syntax
fn extract_async_data(&self, async_reply : &str) -> Result<String, SecureBlackboxError>
Remarks
Call this method before finalizing the asynchronous signing process to extract the data passed to the ExternalCrypto.Data property on the pre-signing stage.
The Data parameter can be used to pass some state or document identifier along with the signing request from the pre-signing to the completion async stage.
get_inner_xml method (XMLSigner Struct)
Get the inner XML content of the selected XML element.
Syntax
fn get_inner_xml(&self, xpath : &str) -> Result<String, SecureBlackboxError>
Remarks
Call this method to get the inner XML content of the selected XML element.
get_outer_xml method (XMLSigner Struct)
Get the outer XML content of the selected XML element.
Syntax
fn get_outer_xml(&self, xpath : &str) -> Result<String, SecureBlackboxError>
Remarks
Call this method to get the outer XML content of the selected XML element.
get_text_content method (XMLSigner Struct)
Get the text content of the selected XML element.
Syntax
fn get_text_content(&self, xpath : &str) -> Result<String, SecureBlackboxError>
Remarks
Call this method to get the text content of the selected XML element.
reset method (XMLSigner Struct)
Resets the struct settings.
Syntax
fn reset(&self) -> Result<(), SecureBlackboxError>
Remarks
reset is a generic method available in every struct.
set_inner_xml method (XMLSigner Struct)
Set the inner XML content of the selected XML element.
Syntax
fn set_inner_xml(&self, xpath : &str, value : &str) -> Result<(), SecureBlackboxError>
Remarks
Call this method to set the inner XML content of the selected XML element.
set_text_content method (XMLSigner Struct)
Set the text content of the selected XML element.
Syntax
fn set_text_content(&self, xpath : &str, value : &str) -> Result<(), SecureBlackboxError>
Remarks
Call this method to set the text content of the selected XML element.
sign method (XMLSigner Struct)
Signs an XML document.
Syntax
fn sign(&self) -> Result<(), SecureBlackboxError>
Remarks
Call this method to generate a signature over an XML document.
sign_async_begin method (XMLSigner Struct)
Initiates the asynchronous signing operation.
Syntax
fn sign_async_begin(&self) -> Result<String, SecureBlackboxError>
Remarks
When using the DC framework, call this method to initiate the asynchronous signing process. Upon completion, a pre-signed copy of the document will be saved in output_file (or output_stream). Keep the pre-signed copy somewhere local, and pass the returned string ('the request state') to the DC processor for handling.
Upon receiving the response state from the DC processor, assign the path to the pre-signed copy to input_file (or input_stream), and call sign_async_end to finalize the signing.
Note that depending on the signing method and DC configuration used, you may still need to provide the public part of the signing certificate via the signing_certificate property.
Use the ExternalCrypto.AsyncDocumentID property to supply a unique document ID to include in the request. This is helpful when creating batches of multiple async requests, as it allows you to pass the whole response batch to sign_async_end and expect it to recover the correct response from the batch automatically.
AsyncState is a message of the distributed cryptography (DC) protocol. The DC protocol is based on the exchange of async states between a DC client (an application that wants to sign a PDF, XML, or Office document) and a DC server (an application that controls access to the private key). An async state can carry one or more signing requests, comprised of document hashes, or one or more signatures produced over those hashes.
In a typical scenario you get a client-side async state from the sign_async_begin method. This state contains document hashes to be signed on the DC server side. You then send the async state to the DC server (often represented by the DCAuth struct), which processes it and produces a matching signature state. The async state produced by the server is then passed to the sign_async_end method.
sign_async_end method (XMLSigner Struct)
Completes the asynchronous signing operation.
Syntax
fn sign_async_end(&self, async_reply : &str) -> Result<(), SecureBlackboxError>
Remarks
When using the DC framework, call this method upon receiving the response state from the DC processor to complete the asynchronous signing process.
Before calling this method, assign the path to the pre-signed copy of the document obtained from the prior sign_async_begin call to input_file (or input_stream). The method will embed the signature into the pre-signed document, and save the complete signed document to output_file (or output_stream).
Note that depending on the signing method and DC configuration used, you may still need to provide the public part of the signing certificate via the signing_certificate property.
Use the ExternalCrypto.AsyncDocumentID parameter to pass a specific document ID if using batched AsyncReply. If used, it should match the value provided on the pre-signing (sign_async_begin) stage.
AsyncState is a message of the distributed cryptography (DC) protocol. The DC protocol is based on the exchange of async states between a DC client (an application that wants to sign a PDF, XML, or Office document) and a DC server (an application that controls access to the private key). An async state can carry one or more signing requests, comprised of document hashes, or one or more signatures produced over those hashes.
In a typical scenario you get a client-side async state from the sign_async_begin method. This state contains document hashes to be signed on the DC server side. You then send the async state to the DC server (often represented by the DCAuth struct), which processes it and produces a matching signature state. The async state produced by the server is then passed to the sign_async_end method.
sign_external method (XMLSigner Struct)
Signs the document using an external signing facility.
Syntax
fn sign_external(&self) -> Result<(), SecureBlackboxError>
Remarks
Call this method to delegate the low-level signing operation to an external, remote, or custom signing engine. This method is useful if the signature has to be made by a device accessible through a custom or non-standard signing interface.
When all preparations are done and hash is computed, the struct fires on_external_sign event which allows to pass the hash value for signing.
on_error event (XMLSigner Struct)
Reports the details of signing errors.
Syntax
// XMLSignerErrorEventArgs carries the XMLSigner Error event's parameters.
pub struct XMLSignerErrorEventArgs {
fn error_code(&self) -> i32
fn description(&self) -> &String
}
// XMLSignerErrorEvent defines the signature of the XMLSigner Error event's handler function.
pub trait XMLSignerErrorEvent {
fn on_error(&self, sender : XMLSigner, e : &mut XMLSignerErrorEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_error(&self) -> &'a dyn XMLSignerErrorEvent;
pub fn set_on_error(&mut self, value : &'a dyn XMLSignerErrorEvent);
...
}
Remarks
The event is fired in case of exceptional conditions during signing.
ErrorCode contains an error code and Description contains a textual description of the error. For a list of valid error codes and their descriptions, please refer to XML.
on_external_sign event (XMLSigner Struct)
Handles remote or external signing initiated by the SignExternal method or other source.
Syntax
// XMLSignerExternalSignEventArgs carries the XMLSigner ExternalSign event's parameters.
pub struct XMLSignerExternalSignEventArgs {
fn operation_id(&self) -> &String
fn hash_algorithm(&self) -> &String
fn pars(&self) -> &String
fn data(&self) -> &String
fn signed_data(&self) -> &String
fn set_signed_data(&self, value : &str)
fn set_signed_data_ref(&self, value : &String)
}
// XMLSignerExternalSignEvent defines the signature of the XMLSigner ExternalSign event's handler function.
pub trait XMLSignerExternalSignEvent {
fn on_external_sign(&self, sender : XMLSigner, e : &mut XMLSignerExternalSignEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_external_sign(&self) -> &'a dyn XMLSignerExternalSignEvent;
pub fn set_on_external_sign(&mut self, value : &'a dyn XMLSignerExternalSignEvent);
...
}
Remarks
Assign a handler to this event if you need to delegate a low-level signing operation to an external, remote, or custom signing engine. Depending on the settings, the handler will receive a hashed or unhashed value to be signed.
The event handler must pass the value of Data to the signer, obtain the signature, and pass it back to the struct via the SignedData parameter.
OperationId provides a comment about the operation and its origin. It depends on the exact struct being used, and may be empty. HashAlgorithm specifies the hash algorithm being used for the operation, and Pars contains algorithm-dependent parameters.
The struct uses base16 (hex) encoding for the Data, SignedData, and Pars parameters. If your signing engine uses a different input and output encoding, you may need to decode and/or encode the data before and/or after the signing.
A sample MD5 hash encoded in base16: a0dee2a0382afbb09120ffa7ccd8a152 - lower case base16 A0DEE2A0382AFBB09120FFA7CCD8A152 - upper case base16
A sample event handler that uses the .NET RSACryptoServiceProvider class may look like the following:
signer.OnExternalSign += (s, e) =>
{
var cert = new X509Certificate2("cert.pfx", "", X509KeyStorageFlags.Exportable);
var key = (RSACryptoServiceProvider)cert.PrivateKey;
var dataToSign = e.Data.FromBase16String();
var signedData = key.SignHash(dataToSign, "2.16.840.1.101.3.4.2.1");
e.SignedData = signedData.ToBase16String();
};
on_format_element event (XMLSigner Struct)
Reports the XML element that is currently being processed.
Syntax
// XMLSignerFormatElementEventArgs carries the XMLSigner FormatElement event's parameters.
pub struct XMLSignerFormatElementEventArgs {
fn start_tag_whitespace(&self) -> &String
fn set_start_tag_whitespace(&self, value : &str)
fn set_start_tag_whitespace_ref(&self, value : &String)
fn end_tag_whitespace(&self) -> &String
fn set_end_tag_whitespace(&self, value : &str)
fn set_end_tag_whitespace_ref(&self, value : &String)
fn level(&self) -> i32
fn path(&self) -> &String
fn has_child_elements(&self) -> bool
}
// XMLSignerFormatElementEvent defines the signature of the XMLSigner FormatElement event's handler function.
pub trait XMLSignerFormatElementEvent {
fn on_format_element(&self, sender : XMLSigner, e : &mut XMLSignerFormatElementEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_format_element(&self) -> &'a dyn XMLSignerFormatElementEvent;
pub fn set_on_format_element(&mut self, value : &'a dyn XMLSignerFormatElementEvent);
...
}
Remarks
Path and Level specify the path to the XML element being processed and its nesting level, respectively.
HasChildElements specify if processed XML element has child elements.
Among other purposes, this event may be used to add whitespace formatting before or after a particular element in the signature.
on_format_text event (XMLSigner Struct)
Reports XML text that is currently being processed.
Syntax
// XMLSignerFormatTextEventArgs carries the XMLSigner FormatText event's parameters.
pub struct XMLSignerFormatTextEventArgs {
fn text(&self) -> &String
fn set_text(&self, value : &str)
fn set_text_ref(&self, value : &String)
fn text_type(&self) -> i32
fn level(&self) -> i32
fn path(&self) -> &String
}
// XMLSignerFormatTextEvent defines the signature of the XMLSigner FormatText event's handler function.
pub trait XMLSignerFormatTextEvent {
fn on_format_text(&self, sender : XMLSigner, e : &mut XMLSignerFormatTextEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_format_text(&self) -> &'a dyn XMLSignerFormatTextEvent;
pub fn set_on_format_text(&mut self, value : &'a dyn XMLSignerFormatTextEvent);
...
}
Remarks
TextType parameter specifies the type of the XML text (normal or Base64-encoded) that is stored in the element; Path and Level specify the path to the XML element and its nesting level.
Among other purposes, this event may be used to add whitespace formatting before or after a particular element in the signature.
on_notification event (XMLSigner Struct)
This event notifies the application about an underlying control flow event.
Syntax
// XMLSignerNotificationEventArgs carries the XMLSigner Notification event's parameters.
pub struct XMLSignerNotificationEventArgs {
fn event_id(&self) -> &String
fn event_param(&self) -> &String
}
// XMLSignerNotificationEvent defines the signature of the XMLSigner Notification event's handler function.
pub trait XMLSignerNotificationEvent {
fn on_notification(&self, sender : XMLSigner, e : &mut XMLSignerNotificationEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_notification(&self) -> &'a dyn XMLSignerNotificationEvent;
pub fn set_on_notification(&mut self, value : &'a dyn XMLSignerNotificationEvent);
...
}
Remarks
The struct fires this event to let the application know about some event, occurrence, or milestone in the struct. For example, it may fire to report completion of the document processing. The list of events being reported is not fixed, and may be flexibly extended over time.
The unique identifier of the event is provided in the EventID parameter. EventParam contains any parameters accompanying the occurrence. Depending on the type of the struct, the exact action it is performing, or the document being processed, one or both may be omitted.
This struct can fire this event with the following EventID values:
| DocumentLoaded | Notifies the application that the document has been loaded. This is a backward-compatibility-only notification. Use OnDocumentLoaded event instead. |
| SignaturesLoaded | Notifies the application that the component has finished loading signatures. |
| RetrieveQualifyingProperties | TBD |
| BeforeTimestamp | This event is fired before a timestamp is requested from the timestamping authority. Use the event handler to modify TSA and HTTP settings. |
| TimestampError | This event is only fired if the struct failed to obtain a timestamp from the timestamping authority. The EventParam parameter contains extended error info. |
| TimestampRequest | A timestamp is requested from the custom timestamping
authority. This event is only fired if timestamp_server was set to a
virtual:// URI. The EventParam parameter contains the
TSP request (or the plain hash, depending on the value provided to
timestamp_server), in base16, that needs to be sent to the TSA.
Use the event handler to send the request to the TSA. Upon receiving the response, assign it, in base16, to the TimestampResponse configuration property. |
on_resolve_reference event (XMLSigner Struct)
Asks the application to resolve a reference.
Syntax
// XMLSignerResolveReferenceEventArgs carries the XMLSigner ResolveReference event's parameters.
pub struct XMLSignerResolveReferenceEventArgs {
fn reference_index(&self) -> i32
fn uri(&self) -> &String
}
// XMLSignerResolveReferenceEvent defines the signature of the XMLSigner ResolveReference event's handler function.
pub trait XMLSignerResolveReferenceEvent {
fn on_resolve_reference(&self, sender : XMLSigner, e : &mut XMLSignerResolveReferenceEventArgs);
}
impl <'a> XMLSigner<'a> {
pub fn on_resolve_reference(&self) -> &'a dyn XMLSignerResolveReferenceEvent;
pub fn set_on_resolve_reference(&mut self, value : &'a dyn XMLSignerResolveReferenceEvent);
...
}
Remarks
This event is fired when the control could not automatically resolve a reference and requires custom treatment.
URI contains a reference to the data.
ReferenceIndex specifies the index of the reference to process.
Based on the reference's URI the event handler should set either TargetXMLElement or TargetData property of the reference.
Config Settings (XMLSigner Struct)
The struct accepts one or more of the following configuration settings. Configuration settings are similar in functionality to properties, but they are rarely used. In order to avoid "polluting" the property namespace of the struct, access to these internal properties is provided through the config method.XMLSigner Config Settings
The default value is 1 day (86400 seconds). A value of 0 disables the absolute CRL age check. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
The default value is 50 percent. Values are interpreted in the 0..100 range. A value of 0 disables the CRL ratio check. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
The default value is 10 minutes (600 seconds). A value of 0 disables the CRL overlap check. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
This setting is evaluated independently from CachedCRLMaxAge and CachedCRLMaxAgeRatio. If several cached CRL freshness settings are enabled, the cached CRL is used only if it satisfies all of them.
The default value is 1 hour (3600 seconds). A value of 0 disables the absolute OCSP response age check. This setting is also used to limit open-ended OCSP responses that do not have NextUpdate. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
The default value is 50 percent. Values are interpreted in the 0..100 range. Open-ended OCSP responses without NextUpdate ignore this setting; use CachedOCSPResponseMaxAge to limit their age. A value of 0 disables the OCSP response ratio check. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
The default value is 10 minutes (600 seconds). A value of 0 disables the OCSP response overlap check. See RevocationCacheAgePolicy for configuring this setting together with the related cached revocation freshness settings.
This setting is evaluated independently from CachedOCSPResponseMaxAge and CachedOCSPResponseMaxAgeRatio. If several cached OCSP response freshness settings are enabled, the cached OCSP response is used only if it satisfies all of them.
For example, if the corresponding ds:Reference element has an Id "reference-id-1", then you should set this property to "#reference-id-1" value.
Index value could be omitted for the first DataObjectFormat element.
The following data types are supported:
| "" or "XML" | an XML document (by default). | |
| "data" | a binary data. |
The default value is dcrlpPreferComplete (1).
Supported values:
- dcrlpPreferDelta (0): retrieve and use delta CRLs when available, falling back to complete CRLs when needed.
- dcrlpPreferComplete (1): try complete CRLs first, and use delta CRLs only if complete CRLs cannot be retrieved.
Default value is "ec". In this case "ec:" prefix will be used.
Special values:
| "#default" or "" | indicates that the prefix will be omitted. |
| "#auto" | indicates that the prefix will be auto-detected based on the parent nodes. |
If IgnoreSystemTrust is True, certificates residing in the trusted root store are treated as if they are known, rather than trusted. Only certificates provided via other means (such as the trusted_certificates property) are considered trusted.
| "" or "XML" | an XML document (by default). | |
| "data" | a binary data. | |
| "base64" | Base64 encoded binary data (input data will be encoded in Base64 and will be placed in ds:Object for Enveloping signature type) |
| Enveloped signature type supports only an XML document as the input. | |
| Enveloping signature type supports all types of the input. | |
| Detached signature type supports an XML document and a binary data as the input. |
Supported values are:
| "" | an empty string indicates the Document element |
| "#id" | indicates an XML element with specified Id |
| XPath expression | indicates an XML element selected using XPath expression. Use add_known_namespace method to specify Prefixes and NamespaceURIs
For example: "/root/data[1]" - indicates the second "data" element under the document element with a name "root" "//ns1:data" - indicates a data element. "ns1" prefix should be defined via add_known_namespace method. |
| Node name | indicates an XML element selected using its NodeName.
For example: "data" - indicates an XML element with node name "data". |
The empty elements in the custom XML content act as a placeholder for auto-generated elements.
For example to change the order of ds:KeyValue and ds:X509Data auto-generated elements use the value: "<X509Data/><KeyValue/>"
Supported values are:
| certificate | Base64-encoded [X509v3] certificate is placed to the signature | |
| issuerserial | X.509 issuer distinguished name/serial number pair are placed to the signature | |
| subjectname | X.509 subject distinguished name is placed to the signature | |
| ski | Base64 encoded plain (i.e. non-DER-encoded) value of a X509 V.3 SubjectKeyIdentifier extension is placed to the signature | |
| crl | Base64-encoded certificate revocation list (CRL) is placed to the signature |
Sample value: '{"addressCountry": "UK", "addressLocality": "London", "postalCode": "N1 7GU", "streetAddress": "20-22 Wenlock Road"}'
Supported values are:
| SigAndRefs | SigAndRefs timestamp | |
| RefsOnly | RefsOnly timestamp |
Supported values are case-insensitive:
| Default | Applies the AdES default freshness settings: crl:86400;50;600,ocsp:3600;50;600. This means: CRL maximum age 1 day, CRL age ratio 50%, CRL overlap 10 minutes; OCSP response maximum age 1 hour, OCSP response age ratio 50%, OCSP response overlap 10 minutes. This value is the default. |
| Disabled | Sets CachedCRLOverlapTime, CachedOCSPResponseOverlapTime, CachedCRLMaxAge, CachedOCSPResponseMaxAge, CachedCRLMaxAgeRatio, and CachedOCSPResponseMaxAgeRatio to 0. It only disables the cache-age freshness policy; it does not disable revocation checking or use of the revocation cache. |
| Short | Uses crl:43200;50;300,ocsp:1800;50;300. This means: CRL maximum age 12 hours, CRL age ratio 50%, CRL overlap 5 minutes; OCSP response maximum age 30 minutes, OCSP response age ratio 50%, OCSP response overlap 5 minutes. |
| Long | Uses crl:518400;50;3600,ocsp:21600;50;3600. This means: CRL maximum age 6 days, CRL age ratio 50%, CRL overlap 1 hour; OCSP response maximum age 6 hours, OCSP response age ratio 50%, OCSP response overlap 1 hour. |
| N | Interprets N as an integer number of seconds. The overlap settings are set to N seconds, CRL maximum age is set to N * 144, OCSP response maximum age is set to N * 6, and both ratio settings are set to 50. |
| crl:<maxAge>;<ratio>;<overlap>,ocsp:<maxAge>;<ratio>;<overlap> | Sets the CRL and OCSP response freshness values explicitly. |
Ratios must be in the 0..100 range. Maximum age and overlap values must be non-negative. Short and Long are time-scale profiles: Long allows older cached revocation information by increasing maximum ages, but also uses a larger pre-expiry safety margin by increasing overlap times. For individual CachedCRLOverlapTime, CachedOCSPResponseOverlapTime, CachedCRLMaxAge, CachedOCSPResponseMaxAge, CachedCRLMaxAgeRatio, and CachedOCSPResponseMaxAgeRatio settings, a value of 0 disables the corresponding freshness check. The individual settings remain available for advanced configuration and can be used after this setting to override specific values.
This setting is used to provide parameters for some cryptographic schemes. Use the Name1=Value1;Name2=Value2;... syntax to encode the parameters. For example: Scheme=PSS;SaltSize=32;TrailerField=1.
Supported values are:
| "" | The same as "XML-DSig". | |
| XML-DSig | The W3C's XMLDSig-compliant signature (by default). | |
| EBICS | Electronic Banking Internet Communication Standard (EBICS) compliant signature. On signing the version is autodetected based on the document element. | |
| EBICS_H3 | Electronic Banking Internet Communication Standard (EBICS) compliant signature. The version is H3. | |
| EBICS_H4 | Electronic Banking Internet Communication Standard (EBICS) compliant signature. The version is H4. | |
| EBICS_H5 | Electronic Banking Internet Communication Standard (EBICS) compliant signature. The version is H5. |
Default value is "ds". In this case "ds:" prefix will be used.
Special values:
| "#default" or "" | indicates that the prefix will be omitted. |
| "#auto" | indicates that the prefix will be auto-detected based on the parent nodes. |
| cxcmNone | 0 | |
| cxcmCanon | 1 | |
| cxcmCanonComment | 2 | |
| cxcmExclCanon | 3 | |
| cxcmExclCanonComment | 4 | |
| cxcmMinCanon | 5 | |
| cxcmCanon_v1_1 | 6 | |
| cxcmCanonComment_v1_1 | 7 |
Supported values:
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 |
The default value is empty string, in this case, the hash algorithm specified in hash_algorithm property is used.
Supported values:
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 |
The default value is empty string, in this case, the hash algorithm specified in hash_algorithm property is used.
Supported values:
| YYYY | Year (e.g. 1997) | |
| YYYY-MM | Year and month (e.g. 1997-07) | |
| YYYY-MM-DD | Complete date (e.g. 1997-07-16) | |
| YYYY-MM-DDThh:mmTZD | Complete date plus hours and minutes (e.g. 1997-07-16T19:20+01:00) | |
| YYYY-MM-DDThh:mm:ssTZD | Complete date plus hours, minutes and seconds (e.g. 1997-07-16T20:20:30Z) | |
| YYYY-MM-DDThh:mm:ss.sTZD | Complete date plus hours, minutes, seconds and a decimal fraction of a second (e.g. 1997-07-16T20:20:30.4Z) | |
| YYYY-MM-DDThh:mm:ss.sssTZD | Default. Complete date plus hours, minutes, seconds and a fraction of a second (e.g. 1997-07-16T20:20:30.451Z) |
Behavior:
| "true" | Default. The provided time is interpreted as UTC. If SigningTimeZoneOffset is non-zero, the time is converted to the corresponding local time (UTC plus the offset) and serialized with that offset; otherwise it is serialized as UTC. | |
| "false" | The provided time is interpreted as local time. No clock-time adjustment is performed. The value is serialized as local time; if SigningTimeZoneOffset is non-zero, the specified offset is included. |
| cxcmNone | 0 | |
| cxcmCanon | 1 | |
| cxcmCanonComment | 2 | |
| cxcmExclCanon | 3 | |
| cxcmExclCanonComment | 4 | |
| cxcmMinCanon | 5 | |
| cxcmCanon_v1_1 | 6 | |
| cxcmCanonComment_v1_1 | 7 |
Supported values are:
| certificate | Base64-encoded [X509v3] certificates | |
| crl | Base64-encoded certificate revocation lists (CRL) | |
| ocsp | OCSP responses |
- CA, revocation source, TLS key usage requirements are not mandated
- Violation of OCSP issuer requirements are ignored
- The AuthorityKeyID extension in CRL- and certificate-issuing CAs are ignored (helps with incorrectly renewed certificates)
- Basic constraints and name constraints of CA certificates are ignored
- Some weaker algorithms are tolerated
In case of a timestamping failure, provide new TSA and HTTP settings inside the on_notification event handler ('BeforeTimestamp' and 'TimestampError' event IDs).
Note: Unlike other structs, PDFSigner struct uses the same hash algorithm for the main signature and any associated timestamps during signing. Use this property to specify a different hash algorithm for the timestamp.
The following default TSLs are used: EU (European Union) LOTL (list of trusted lists).
The following default TSLs are used: EU (European Union) LOTL (list of trusted lists).
Supported values are:
| certificate | References to X.509 certificates | |
| crl | References to certificate revocation lists (CRL) | |
| ocsp | References to OCSP responses |
Supported values:
| SB_HASH_ALGORITHM_MD5 | MD5 | |
| SB_HASH_ALGORITHM_SHA1 | SHA1 | |
| SB_HASH_ALGORITHM_SHA224 | SHA224 | |
| SB_HASH_ALGORITHM_SHA256 | SHA256 | |
| SB_HASH_ALGORITHM_SHA384 | SHA384 | |
| SB_HASH_ALGORITHM_SHA512 | SHA512 | |
| SB_HASH_ALGORITHM_RIPEMD160 | RIPEMD160 | |
| SB_HASH_ALGORITHM_GOST_R3411_1994 | GOST1994 | |
| SB_HASH_ALGORITHM_WHIRLPOOL | WHIRLPOOL | |
| SB_HASH_ALGORITHM_SHA3_256 | SHA3_256 | |
| SB_HASH_ALGORITHM_SHA3_384 | SHA3_384 | |
| SB_HASH_ALGORITHM_SHA3_512 | SHA3_512 |
The default value is empty string, in this case, the hash algorithm specified in hash_algorithm property is used.
Supported values are:
| certificate | Base64-encoded [X509v3] certificates | |
| crl | Base64-encoded certificate revocation lists (CRL) | |
| ocsp | OCSP responses |
Default value is "xades". In this case "xades:" prefix will be used.
Special values:
| "#default" or "" | indicates that the prefix will be omitted. |
| "#auto" | indicates that the prefix will be auto-detected based on the parent nodes. |
Default value is "xadesv141". In this case "xadesv141:" prefix will be used.
Special values:
| "#default" or "" | indicates that the prefix will be omitted. |
| "#auto" | indicates that the prefix will be auto-detected based on the parent nodes. |
Supported values:
| "" or "none" | no formatting (by default). | |
| "auto" | enables auto-formatting, equivalent to: "indent: 1; indent-char: tab; base64-max-length: 64; starting-level: node" |
| indent | specifies indentation level (default is 1) | |
| indent-char | specifies indentation character: "space" or "tab" (default) | |
| base64-max-length | specifies max length of base64 encoded data, such as signature value, certificate data and etc. (default is 64) | |
| starting-level | specifies starting indentation level: non-negative integer or "node" - detected based on parent node, or "root" - detected based on number of parent nodes to a document element (default is "node"). | |
| indent-before-main | specifies if whitespace characters should be inserted before a main (ds:Signature) element: "auto" (default), "yes" or "no" |
Supported values:
- cxcmNone (0)
- cxcmCanon (1)
- cxcmCanonComment (2)
- cxcmExclCanon (3)
- cxcmExclCanonComment (4)
- cxcmMinCanon (5)
- cxcmCanon_v1_1 (6)
Supported values:
| "completefragment" | as complete fragment (the default setting). | |
| "rawtree" | as a raw tree |
Base Config Settings
You can switch this property off to improve performance if your project only uses known, good private keys.
Supported values are:
| off | No caching (default) | |
| local | Local caching | |
| global | Global caching |
This setting only applies to sessions negotiated with TLS version 1.3.
Supported Values:
| auto | Use hardware cryptography if available; otherwise, fall back to software-based cryptography (default). |
| enable | Always attempt to use hardware cryptography. If unavailable, exception will be thrown. |
| disable | Do not use hardware cryptography. |
Supported values are:
| file | File | |
| console | Console | |
| systemlog | System Log (supported for Android only) | |
| debugger | Debugger (supported for VCL for Windows and .Net) |
Supported values are:
| time | Current time | |
| level | Level | |
| package | Package name | |
| module | Module name | |
| class | Class name | |
| method | Method name | |
| threadid | Thread Id | |
| contenttype | Content type | |
| content | Content | |
| all | All details |
Supported filter names are:
| exclude-package | Exclude a package specified in the value | |
| exclude-module | Exclude a module specified in the value | |
| exclude-class | Exclude a class specified in the value | |
| exclude-method | Exclude a method specified in the value | |
| include-package | Include a package specified in the value | |
| include-module | Include a module specified in the value | |
| include-class | Include a class specified in the value | |
| include-method | Include a method specified in the value |
| none | No flush (caching only) | |
| immediate | Immediate flush (real-time logging) | |
| maxcount | Flush cached entries upon reaching LogMaxEventCount entries in the cache. |
Supported values are:
| none | None (by default) | |
| fatal | Severe errors that cause premature termination. | |
| error | Other runtime errors or unexpected conditions. | |
| warning | Use of deprecated APIs, poor use of API, 'almost' errors, other runtime situations that are undesirable or unexpected, but not necessarily "wrong". | |
| info | Interesting runtime events (startup/shutdown). | |
| debug | Detailed information on flow of through the system. | |
| trace | More detailed information. |
The default value of this setting is 100.
| none | No rotation | |
| deleteolder | Delete older entries from the cache upon reaching LogMaxEventCount | |
| keepolder | Keep older entries in the cache upon reaching LogMaxEventCount (newer entries are discarded) |
Supported Values:
| certificate | Enables caching of certificates. |
| crl | Enables caching of Certificate Revocation Lists (CRLs). |
| ocsp | Enables caching of OCSP (Online Certificate Status Protocol) responses. |
Example (default value):
PKICache=certificate,crl,ocsp
In this example, the component caches certificates, CRLs, and OCSP responses.
The default value is an empty string - no cached PKI data is stored on disk.
Example:
PKICachePath=C:\Temp\cache
In this example, the cached PKI data is stored in the C:\Temp\cache directory.
Supported values are:
| none | No static DNS rules (default) | |
| local | Local static DNS rules | |
| global | Global static DNS rules |
This setting only applies to certificates originating from a Windows system store.
The property accepts comma-separated values where the first descriptor name is used when the OID is mapped, and subsequent values act as aliases for parsing.
Syntax:
Config("XMLRDNDescriptorName[OID]=PrimaryName,Alias1,Alias2");
Where:
OID: The Object Identifier from the certificate's IssuerRDN or SubjectRDN that you want to map.
PrimaryName: The main descriptor name used in the XML signature when the OID is encountered.
Alias1, Alias2, ...: Optional alternative names recognized during parsing.
Usage Examples:
Map OID 2.5.4.5 to SERIALNUMBER:
Config("XMLRDNDescriptorName[2.5.4.5]=SERIALNUMBER");
Map OID 1.2.840.113549.1.9.1 to E, with aliases EMAIL and EMAILADDRESS:
Config("XMLRDNDescriptorName[1.2.840.113549.1.9.1]=E,EMAIL,EMAILADDRESS");
Trappable Errors (XMLSigner Struct)
XMLSigner Errors
| 1048577 | Invalid parameter (SB_ERROR_INVALID_PARAMETER) |
| 1048578 | Invalid configuration (SB_ERROR_INVALID_SETUP) |
| 1048579 | Invalid state (SB_ERROR_INVALID_STATE) |
| 1048580 | Invalid value (SB_ERROR_INVALID_VALUE) |
| 1048581 | Private key not found (SB_ERROR_NO_PRIVATE_KEY) |
| 1048582 | Cancelled by the user (SB_ERROR_CANCELLED_BY_USER) |
| 1048583 | The file was not found (SB_ERROR_NO_SUCH_FILE) |
| 1048584 | Unsupported feature or operation (SB_ERROR_UNSUPPORTED_FEATURE) |
| 1048585 | General error (SB_ERROR_GENERAL_ERROR) |
| 39845889 | The input file does not exist (SB_ERROR_XML_INPUTFILE_NOT_EXISTS) |
| 39845890 | Data file does not exist (SB_ERROR_XML_DATAFILE_NOT_EXISTS) |
| 39845892 | Unsupported hash algorithm (SB_ERROR_XML_UNSUPPORTED_HASH_ALGORITHM) |
| 39845893 | Unsupported key type (SB_ERROR_XML_UNSUPPORTED_KEY_TYPE) |
| 39845895 | Unsupported encryption algorithm (SB_ERROR_XML_INVALID_ENCRYPTION_METHOD) |
| 39845896 | XML element not found (SB_ERROR_XML_NOT_FOUND) |
| 39845897 | XML element has no ID (SB_ERROR_XML_NO_ELEMENT_ID) |