Class DeferredSignerBuilder
- Namespace
- SimpleSign.PAdES
- Assembly
- SimpleSign.PAdES.dll
Fluent builder for deferred (two-phase) PAdES signing. Immutable — each method returns a new instance with updated configuration.
public sealed class DeferredSignerBuilder
- Inheritance
-
DeferredSignerBuilder
- Inherited Members
Remarks
Create instances through Document(byte[]). Configure all PDF-field data with WithFieldOptions(SignatureFieldOptions) and enrichment with WithLevel(AdesBaselineProfile).
Methods
CompleteAsync(byte[], CancellationToken)
Completes the session supplied to Resume(byte[], byte[]).
public Task<byte[]> CompleteAsync(byte[] rawSignature, CancellationToken cancellationToken = default)
Parameters
rawSignaturebyte[]Raw signature bytes produced by the external signer.
cancellationTokenCancellationTokenCancellation token.
Returns
PrepareAsync(CancellationToken)
Phase 1: Prepares the document and returns the hash to be signed. The hash must be signed by the external signer (e.g., hardware token, browser).
public Task<DeferredSigningPrepareResult> PrepareAsync(CancellationToken cancellationToken = default)
Parameters
cancellationTokenCancellationToken
Returns
SignAsync(byte[], CancellationToken)
One-shot signing: Prepares the hash and immediately completes the signature. Use this when the signing happens synchronously on the same machine.
public Task<byte[]> SignAsync(byte[] signature, CancellationToken cancellationToken = default)
Parameters
signaturebyte[]cancellationTokenCancellationToken
Returns
WithCertificate(X509Certificate2)
Sets the certificate used to verify the raw external signature.
public DeferredSignerBuilder WithCertificate(X509Certificate2 certificate)
Parameters
certificateX509Certificate2
Returns
WithCertificate(X509Certificate2, IReadOnlyList<X509Certificate2>)
Sets the certificate and certificate chain included in the CMS.
public DeferredSignerBuilder WithCertificate(X509Certificate2 certificate, IReadOnlyList<X509Certificate2> chain)
Parameters
certificateX509Certificate2chainIReadOnlyList<X509Certificate2>
Returns
WithFieldOptions(SignatureFieldOptions)
Replaces the complete PDF signature field configuration.
public DeferredSignerBuilder WithFieldOptions(SignatureFieldOptions fieldOptions)
Parameters
fieldOptionsSignatureFieldOptions
Returns
WithHashAlgorithm(HashAlgorithmName)
Sets the hash algorithm for the signature. Default: SHA-256.
public DeferredSignerBuilder WithHashAlgorithm(HashAlgorithmName algorithm)
Parameters
algorithmHashAlgorithmName
Returns
WithHttpClientProvider(IHttpClientProvider)
Sets the fallback HTTP provider used by timestamp and LTV completion.
public DeferredSignerBuilder WithHttpClientProvider(IHttpClientProvider provider)
Parameters
providerIHttpClientProvider
Returns
WithLevel(AdesBaselineProfile)
Sets the complete ADeS baseline profile for completion.
public DeferredSignerBuilder WithLevel(AdesBaselineProfile profile)
Parameters
profileAdesBaselineProfile
Returns
WithLogger(ILogger)
Sets a custom logger for diagnostic output.
public DeferredSignerBuilder WithLogger(ILogger logger)
Parameters
loggerILogger
Returns
WithSessionIntegrityKey(byte[])
Sets the server-owned HMAC key used to authenticate the deferred session. The key must contain at least 32 bytes and is never serialized into the session.
public DeferredSignerBuilder WithSessionIntegrityKey(byte[] key)
Parameters
keybyte[]A server-owned HMAC key with at least 256 bits of entropy.
Returns
- DeferredSignerBuilder
A new preparation builder with the supplied key snapshot.
Exceptions
- InvalidOperationException
Thrown when called on a resumed builder.
WithSignatureAlgorithm(string)
Specifies a custom signature algorithm OID. Default: auto-detected from certificate.
public DeferredSignerBuilder WithSignatureAlgorithm(string oid)
Parameters
oidstring