SignData: CSSM_SignData, CSP_SignData - Sign all buffer data (CDSA)


# include <cssm.h>


Common Security Services Manager library (cdsa$incssm300_shr.exe)

CCHandle (input)
 The handle that describes the context of this cryptographicoperation used to link to the CSP-managed information.
DataBufs (input)
 A pointer to a vector of CSSM_DATA structures thatcontain the data to be signed.
DataBufCount (input)
 The number of DataBufs to be signed.
DigestAlgorithm (input)
 If signing just a digest, specifies the type ofdigest. In this case, the context should only specify the encryptionalgorithm. If not signing just a digest, it must be CSSM_ALGID_NONE.In this case, the context should specify the combination digest/encryptionalgorithm.
Signature (output)
 A pointer to the CSSM_DATA structure for the signature.

CSPHandle (input)
 The handle that describes the add-in CryptographicService Provider module used to perform up calls to CSSM for thememory functions managed by CSSM.
Context (input)
 Pointer to CSSM_CONTEXT structure that describesthe attributes with this context.

This function signs all data contained in the set of inputbuffers using the private key specified in the context. The CSPcan require that the cryptographic context include access credentialsfor authentication and authorization checks when using a privatekey or a secret key.

Signing can include digesting the data and encrypting thedigest or signing just the digest (already calculated by the application).If digesting the data and encrypting the digest, then the contextshould specify the combination digest/encryption algorithm (forexample, CSSM_ALGID_MD5WithRSA). In this case, the DigestAlgorithm parametermust be set to CSSM_ALGID_NONE. If signing just the digest, thenthe context should specify just the encryption algorithm and the DigestAlgorithm parametershould specify the type of digest (for example, CSSM_ALGID_MD5).Also, DataBufCount must be 1.

If the signing algorithm is not reversible or strictly limitsthe size of the signed data, then the algorithm can specify signingwithout digesting. In this case, the sign operation is performedon the input data and the size of the input data is restricted bythe service provider.

The output is returned to the caller either by filling thecaller-specified buffer or by using the application's declared memoryallocation functions to allocate buffer space. To specify a specific,preallocated output buffer, the caller must provide an array ofone or more CSSM_DATA structures each, containing a Length fieldvalue greater than zero and a non-NULL data pointer field value.To specify automatic output buffer allocation by the CSP, the callermust provide an array of one or more CSSM_DATA structures, eachcontaining a Length field value equal to zero and a NULL data pointerfield value. The application is always responsible for deallocatingthe memory when it is no longer needed.

The output is returned to the caller as specifed in BufferManagement for Cryptographic Services.

A CSSM_RETURN value indicating success or specifying a particularerror condition. The value CSSM_OK indicates success. All othervalues represent an error condition.

Errors are described in the CDSA Technical Standard.

Intel CDSA Application Developer's Guide

Online Help

Functions for the CSSM API:

CSSM_VerifyData, CSSM_SignDataInit, CSSM_SignDataUpdate, CSSM_SignDataFinal

Functions for the CSP SPI:

CSP_VerifyData, CSP_SignDataInit, CSP_SignDataUpdate, CSP_SignDataFinal

