Table of Contents

Class DeferredSignerBuilder

Namespace
SimpleSign.PAdES
Assembly
SimpleSign.PAdES.dll

Fluent builder for deferred (two-phase) PAdES signing. Immutable — each method returns a new instance with updated configuration.

public sealed class DeferredSignerBuilder
Inheritance
DeferredSignerBuilder
Inherited Members

Remarks

Create instances through Document(byte[]). Configure all PDF-field data with WithFieldOptions(SignatureFieldOptions) and enrichment with WithLevel(AdesBaselineProfile).

Methods

CompleteAsync(byte[], CancellationToken)

Completes the session supplied to Resume(byte[], byte[]).

public Task<byte[]> CompleteAsync(byte[] rawSignature, CancellationToken cancellationToken = default)

Parameters

rawSignature byte[]

Raw signature bytes produced by the external signer.

cancellationToken CancellationToken

Cancellation token.

Returns

Task<byte[]>

The completed signed PDF.

PrepareAsync(CancellationToken)

Phase 1: Prepares the document and returns the hash to be signed. The hash must be signed by the external signer (e.g., hardware token, browser).

public Task<DeferredSigningPrepareResult> PrepareAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

Task<DeferredSigningPrepareResult>

SignAsync(byte[], CancellationToken)

One-shot signing: Prepares the hash and immediately completes the signature. Use this when the signing happens synchronously on the same machine.

public Task<byte[]> SignAsync(byte[] signature, CancellationToken cancellationToken = default)

Parameters

signature byte[]
cancellationToken CancellationToken

Returns

Task<byte[]>

WithCertificate(X509Certificate2)

Sets the certificate used to verify the raw external signature.

public DeferredSignerBuilder WithCertificate(X509Certificate2 certificate)

Parameters

certificate X509Certificate2

Returns

DeferredSignerBuilder

WithCertificate(X509Certificate2, IReadOnlyList<X509Certificate2>)

Sets the certificate and certificate chain included in the CMS.

public DeferredSignerBuilder WithCertificate(X509Certificate2 certificate, IReadOnlyList<X509Certificate2> chain)

Parameters

certificate X509Certificate2
chain IReadOnlyList<X509Certificate2>

Returns

DeferredSignerBuilder

WithFieldOptions(SignatureFieldOptions)

Replaces the complete PDF signature field configuration.

public DeferredSignerBuilder WithFieldOptions(SignatureFieldOptions fieldOptions)

Parameters

fieldOptions SignatureFieldOptions

Returns

DeferredSignerBuilder

WithHashAlgorithm(HashAlgorithmName)

Sets the hash algorithm for the signature. Default: SHA-256.

public DeferredSignerBuilder WithHashAlgorithm(HashAlgorithmName algorithm)

Parameters

algorithm HashAlgorithmName

Returns

DeferredSignerBuilder

WithHttpClientProvider(IHttpClientProvider)

Sets the fallback HTTP provider used by timestamp and LTV completion.

public DeferredSignerBuilder WithHttpClientProvider(IHttpClientProvider provider)

Parameters

provider IHttpClientProvider

Returns

DeferredSignerBuilder

WithLevel(AdesBaselineProfile)

Sets the complete ADeS baseline profile for completion.

public DeferredSignerBuilder WithLevel(AdesBaselineProfile profile)

Parameters

profile AdesBaselineProfile

Returns

DeferredSignerBuilder

WithLogger(ILogger)

Sets a custom logger for diagnostic output.

public DeferredSignerBuilder WithLogger(ILogger logger)

Parameters

logger ILogger

Returns

DeferredSignerBuilder

WithSessionIntegrityKey(byte[])

Sets the server-owned HMAC key used to authenticate the deferred session. The key must contain at least 32 bytes and is never serialized into the session.

public DeferredSignerBuilder WithSessionIntegrityKey(byte[] key)

Parameters

key byte[]

A server-owned HMAC key with at least 256 bits of entropy.

Returns

DeferredSignerBuilder

A new preparation builder with the supplied key snapshot.

Exceptions

InvalidOperationException

Thrown when called on a resumed builder.

WithSignatureAlgorithm(string)

Specifies a custom signature algorithm OID. Default: auto-detected from certificate.

public DeferredSignerBuilder WithSignatureAlgorithm(string oid)

Parameters

oid string

Returns

DeferredSignerBuilder