Table of Contents

Class XadesSignerBuilder

Namespace
SimpleSign.XAdES
Assembly
SimpleSign.XAdES.dll

Immutable fluent builder for XAdES signatures (ETSI EN 319 132).

[RequiresUnreferencedCode("XAdES uses System.Security.Cryptography.Xml which is not AOT-compatible.")]
[RequiresDynamicCode("XAdES uses System.Security.Cryptography.Xml which is not AOT-compatible.")]
public sealed class XadesSignerBuilder
Inheritance
XadesSignerBuilder
Inherited Members

Methods

SignAsync(CancellationToken)

Signs the XML document and returns the signed bytes.

public Task<byte[]> SignAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

Task<byte[]>

The signed XML bytes.

Remarks

Throws SigningException when the requested level profile is configured for best-effort downgrades; use SignWithDetailsAsync(CancellationToken) in that case.

SignWithDetailsAsync(CancellationToken)

Signs the XML document and returns a detailed result with level facts and warnings.

public Task<XadesSigningResult> SignWithDetailsAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

Task<XadesSigningResult>

The detailed XAdES signing result.

WithCertificate(X509Certificate2)

Sets the signing certificate (must have a private key for local signing).

public XadesSignerBuilder WithCertificate(X509Certificate2 certificate)

Parameters

certificate X509Certificate2

The signing certificate.

Returns

XadesSignerBuilder

A new builder with the local credential configured.

WithCertificate(X509Certificate2, IReadOnlyList<X509Certificate2>)

Sets the signing certificate and its chain.

public XadesSignerBuilder WithCertificate(X509Certificate2 certificate, IReadOnlyList<X509Certificate2> chain)

Parameters

certificate X509Certificate2

The signing certificate.

chain IReadOnlyList<X509Certificate2>

Intermediate CA certificates, ordered from the issuer of certificate up to (but not including) the root. May be empty. The collection is defensively copied.

Returns

XadesSignerBuilder

A new builder with the local credential configured.

WithCommitmentType(CommitmentType)

Sets the commitment type indication (e.g. ProofOfOrigin, ProofOfApproval).

public XadesSignerBuilder WithCommitmentType(CommitmentType commitmentType)

Parameters

commitmentType CommitmentType

The commitment type.

Returns

XadesSignerBuilder

A new builder with the commitment type configured.

WithDataObjectFormat(DataObjectFormat)

Set the data object format (MIME type + object reference URI).

public XadesSignerBuilder WithDataObjectFormat(DataObjectFormat format)

Parameters

format DataObjectFormat

The data object format.

Returns

XadesSignerBuilder

A new builder with the data object format configured.

WithDataUri(string)

Sets the data URI for Detached form signatures.

public XadesSignerBuilder WithDataUri(string dataUri)

Parameters

dataUri string

The data object URI.

Returns

XadesSignerBuilder

A new builder with the data URI configured.

WithExternalSigner(X509Certificate2, IExternalSigner)

Configures external signing (HSM, cloud KMS, A3 token).

public XadesSignerBuilder WithExternalSigner(X509Certificate2 certificate, IExternalSigner signer)

Parameters

certificate X509Certificate2

The signer's public certificate (private key NOT required).

signer IExternalSigner

The external signer implementation.

Returns

XadesSignerBuilder

A new builder with the external credential configured.

WithExternalSigner(X509Certificate2, IExternalSigner, IReadOnlyList<X509Certificate2>)

Configures external signing with a pre-fetched certificate chain.

public XadesSignerBuilder WithExternalSigner(X509Certificate2 certificate, IExternalSigner signer, IReadOnlyList<X509Certificate2> chain)

Parameters

certificate X509Certificate2

The signer's public certificate (private key NOT required).

signer IExternalSigner

The external signer implementation.

chain IReadOnlyList<X509Certificate2>

Intermediate CA certificates, ordered from the issuer of certificate up to (but not including) the root. May be empty. The collection is defensively copied.

Returns

XadesSignerBuilder

A new builder with the external credential configured.

WithForm(XadesForm)

Sets the XAdES signature packaging form (Enveloped, Detached, Enveloping).

public XadesSignerBuilder WithForm(XadesForm form)

Parameters

form XadesForm

The XAdES packaging form.

Returns

XadesSignerBuilder

A new builder with the form configured.

WithHashAlgorithm(HashAlgorithmName)

Sets the hash algorithm (default: SHA-256).

public XadesSignerBuilder WithHashAlgorithm(HashAlgorithmName algorithm)

Parameters

algorithm HashAlgorithmName

The hash algorithm.

Returns

XadesSignerBuilder

A new builder with the hash algorithm configured.

WithHttpClientProvider(IHttpClientProvider)

Sets a builder-wide IHttpClientProvider used as the fallback for all network operations that do not carry their own scoped provider (timestamp, long-term validation material, archive timestamp).

public XadesSignerBuilder WithHttpClientProvider(IHttpClientProvider provider)

Parameters

provider IHttpClientProvider

The HTTP client provider.

Returns

XadesSignerBuilder

A new builder with the provider configured.

WithLevel(AdesBaselineProfile)

Replaces the complete baseline profile. The requested ETSI level and all of its dependencies travel together in one immutable value; no other method changes the level.

public XadesSignerBuilder WithLevel(AdesBaselineProfile profile)

Parameters

profile AdesBaselineProfile

The complete baseline profile (B-B, B-T, B-LT, or B-LTA).

Returns

XadesSignerBuilder

A new builder with the profile configured.

WithLogger(ILogger)

Sets a logger for diagnostic output.

public XadesSignerBuilder WithLogger(ILogger logger)

Parameters

logger ILogger

The logger.

Returns

XadesSignerBuilder

A new builder with the logger configured.

WithOperationId(string)

Sets an operation ID for log correlation.

public XadesSignerBuilder WithOperationId(string operationId)

Parameters

operationId string

The operation ID.

Returns

XadesSignerBuilder

A new builder with the operation ID configured.

WithSignatureAlgorithm(string)

Sets an explicit signature algorithm OID (e.g. RSA PKCS#1, RSA-PSS, ECDSA).

public XadesSignerBuilder WithSignatureAlgorithm(string signatureAlgorithmOid)

Parameters

signatureAlgorithmOid string

The signature algorithm OID.

Returns

XadesSignerBuilder

A new builder with the signature algorithm configured.

WithSignaturePolicy(string, string?)

Sets the signature policy OID and optional policy document URI.

public XadesSignerBuilder WithSignaturePolicy(string oid, string? uri = null)

Parameters

oid string

The signature policy OID.

uri string

Optional policy document URI.

Returns

XadesSignerBuilder

A new builder with the signature policy configured.

WithSignerRole(string)

Set a single claimed signer role.

public XadesSignerBuilder WithSignerRole(string role)

Parameters

role string

The signer role.

Returns

XadesSignerBuilder

A new builder with the signer role configured.

WithSignerRoles(IReadOnlyList<string>)

Set claimed signer role(s) (e.g., "Manager", "Approver").

public XadesSignerBuilder WithSignerRoles(IReadOnlyList<string> roles)

Parameters

roles IReadOnlyList<string>

The signer roles. The collection is defensively copied.

Returns

XadesSignerBuilder

A new builder with the signer roles configured.

WithSigningTime(DateTimeOffset)

Sets the explicit claimed signing time (default: UTC now).

public XadesSignerBuilder WithSigningTime(DateTimeOffset signingTime)

Parameters

signingTime DateTimeOffset

The claimed signing time.

Returns

XadesSignerBuilder

A new builder with the signing time configured.