Table of Contents

Class CadesSignerBuilder

Namespace
SimpleSign.CAdES
Assembly
SimpleSign.CAdES.dll

Immutable fluent builder for CAdES signatures (ETSI EN 319 122). Created via CadesSigner.Document(data) and configured with With* methods that return a new builder instance.

public sealed class CadesSignerBuilder
Inheritance
CadesSignerBuilder
Inherited Members

Methods

SignAsync(CancellationToken)

Signs the data and returns the DER-encoded CMS/PKCS#7 SignedData.

public Task<byte[]> SignAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

Task<byte[]>

The DER-encoded CMS signature bytes.

Remarks

Throws SigningException when the requested level profile is configured for best-effort downgrades; use SignWithDetailsAsync(CancellationToken) in that case.

SignWithDetailsAsync(CancellationToken)

Signs the data and returns a structured result with the CMS bytes, requested and achieved baseline levels, actual feature flags, and warnings.

public Task<CadesSigningResult> SignWithDetailsAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

Task<CadesSigningResult>

The detailed CAdES signing result.

WithCertificate(X509Certificate2)

Sets the signer's certificate (must have a private key for local signing).

public CadesSignerBuilder WithCertificate(X509Certificate2 certificate)

Parameters

certificate X509Certificate2

The signing certificate.

Returns

CadesSignerBuilder

A new builder with the local credential configured.

WithCertificate(X509Certificate2, IReadOnlyList<X509Certificate2>)

Sets the signer's certificate and its chain.

public CadesSignerBuilder WithCertificate(X509Certificate2 certificate, IReadOnlyList<X509Certificate2> chain)

Parameters

certificate X509Certificate2

The signing certificate.

chain IReadOnlyList<X509Certificate2>

Intermediate CA certificates, ordered from the issuer of certificate up to (but not including) the root. May be empty. The collection is defensively copied.

Returns

CadesSignerBuilder

A new builder with the local credential configured.

WithCommitmentType(CommitmentType)

Sets the commitment type indication (e.g. ProofOfOrigin, ProofOfApproval).

public CadesSignerBuilder WithCommitmentType(CommitmentType commitmentType)

Parameters

commitmentType CommitmentType

The commitment type.

Returns

CadesSignerBuilder

A new builder with the commitment type configured.

WithContentType(CadesContentType)

Sets the content type. Detached = .p7s (default), Enveloped = .p7m with embedded data.

public CadesSignerBuilder WithContentType(CadesContentType contentType)

Parameters

contentType CadesContentType

The CAdES content type.

Returns

CadesSignerBuilder

A new builder with the content type configured.

WithExternalSigner(X509Certificate2, IExternalSigner)

Uses an external signer (HSM, cloud KMS, A3 token).

public CadesSignerBuilder WithExternalSigner(X509Certificate2 certificate, IExternalSigner signer)

Parameters

certificate X509Certificate2

The signer's public certificate (private key NOT required).

signer IExternalSigner

The external signer implementation.

Returns

CadesSignerBuilder

A new builder with the external credential configured.

WithExternalSigner(X509Certificate2, IExternalSigner, IReadOnlyList<X509Certificate2>)

Uses an external signer with a pre-fetched certificate chain.

public CadesSignerBuilder WithExternalSigner(X509Certificate2 certificate, IExternalSigner signer, IReadOnlyList<X509Certificate2> chain)

Parameters

certificate X509Certificate2

The signer's public certificate (private key NOT required).

signer IExternalSigner

The external signer implementation.

chain IReadOnlyList<X509Certificate2>

Intermediate CA certificates, ordered from the issuer of certificate up to (but not including) the root. May be empty. The collection is defensively copied.

Returns

CadesSignerBuilder

A new builder with the external credential configured.

WithHashAlgorithm(HashAlgorithmName)

Explicitly sets the hash algorithm. Default: SHA-256.

public CadesSignerBuilder WithHashAlgorithm(HashAlgorithmName algorithm)

Parameters

algorithm HashAlgorithmName

The hash algorithm.

Returns

CadesSignerBuilder

A new builder with the hash algorithm configured.

WithHttpClientProvider(IHttpClientProvider)

Sets a builder-wide IHttpClientProvider used as the fallback for all network operations that do not carry their own scoped provider (timestamp, long-term validation material, archive timestamp).

public CadesSignerBuilder WithHttpClientProvider(IHttpClientProvider provider)

Parameters

provider IHttpClientProvider

The HTTP client provider.

Returns

CadesSignerBuilder

A new builder with the provider configured.

WithLevel(AdesBaselineProfile)

Replaces the complete baseline profile. The requested ETSI level and all of its dependencies travel together in one immutable value; no other method changes the level.

public CadesSignerBuilder WithLevel(AdesBaselineProfile profile)

Parameters

profile AdesBaselineProfile

The complete baseline profile (B-B, B-T, B-LT, or B-LTA).

Returns

CadesSignerBuilder

A new builder with the profile configured.

WithLogger(ILogger)

Sets the logger for diagnostic output.

public CadesSignerBuilder WithLogger(ILogger logger)

Parameters

logger ILogger

The logger.

Returns

CadesSignerBuilder

A new builder with the logger configured.

WithOperationId(string)

Sets an operation ID for log correlation (appears in all log messages produced by this signing operation).

public CadesSignerBuilder WithOperationId(string operationId)

Parameters

operationId string

The operation ID.

Returns

CadesSignerBuilder

A new builder with the operation ID configured.

WithSignatureAlgorithm(string)

Explicitly sets the signature algorithm OID.

public CadesSignerBuilder WithSignatureAlgorithm(string signatureAlgorithmOid)

Parameters

signatureAlgorithmOid string

The signature algorithm OID.

Returns

CadesSignerBuilder

A new builder with the signature algorithm configured.

WithSignaturePolicy(string, string?)

Sets the signature policy identifier and optional URI.

public CadesSignerBuilder WithSignaturePolicy(string oid, string? uri = null)

Parameters

oid string

The signature policy OID.

uri string

Optional policy document URI.

Returns

CadesSignerBuilder

A new builder with the signature policy configured.

WithSigningTime(DateTimeOffset)

Sets an explicit claimed signing time. Default: UTC now.

public CadesSignerBuilder WithSigningTime(DateTimeOffset signingTime)

Parameters

signingTime DateTimeOffset

The claimed signing time.

Returns

CadesSignerBuilder

A new builder with the signing time configured.