Documentation
¶
Overview ¶
Package sign 通过外部命令为 OFD 文档追加签名。
签名在包内容最终确定后追加:本包为每个文档体计算被引用文件的摘要并生成 Signature.xml(SignedInfo),把该文件字节通过标准输入交给外部命令,命令在 标准输出返回 SignedValue.dat 字节,本包再写回 Signatures.xml 与 OFD.xml。 签名算法与私钥由外部命令负责,本包不接触密钥。
Index ¶
Constants ¶
View Source
const ( // DefaultSignatureMethod 是 SM2 + SM3 的签名算法 OID。 DefaultSignatureMethod = "1.2.156.10197.1.501" // DefaultCheckMethod 是默认摘要算法。 DefaultCheckMethod = "SM3" )
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Options ¶
type Options struct {
// Command 是外部签名命令,按空白拆分参数,不支持引号或 shell 语法。
// 命令从标准输入读取 Signature.xml 字节,向标准输出写 SignedValue.dat 字节。
Command string
// ID 是签名标识,空值时使用 "sign-1"。
ID string
// ProviderName、ProviderVersion、Company 写入 SignedInfo 的 Provider。
ProviderName string
ProviderVersion string
Company string
// SignatureMethod 是签名算法 OID,空值时使用 DefaultSignatureMethod。
SignatureMethod string
// CheckMethod 是摘要算法,空值时使用 DefaultCheckMethod。
CheckMethod string
// Date 是签名时间,零值时使用当前时间。
Date time.Time
// Deterministic 使用固定 ZIP 时间,生成可复现的签名结果。
// 需要 Date 固定时配合设置,否则 Signature.xml 中的签名时间仍会变化。
Deterministic bool
// Stamp 控制是否在 Signature.xml 写入 StampAnnot,让阅读器把印章图片绘制到页面上。
// 为 nil 时不写入 StampAnnot(只验签,不显示印章)。
Stamp *StampOptions
// References 控制 SignedInfo/References 覆盖的文件集合;为 nil 时签名文档体目录下的全部文件(不含 OFD.xml)。
References *ReferenceOptions
// Environment 是传递给外部命令的额外环境变量,格式为 KEY=VALUE。
Environment []string
}
Options 控制外部命令签名。
type ReferenceOptions ¶
ReferenceOptions 选择 SignedInfo/References 覆盖的文件。 Include/Exclude 是不区分大小写的 glob(相对文档体目录,如 "Pages/**"、"*.xml"), 为空表示包含全部文件。RootDocument 为真时把 OFD.xml 纳入引用。
type StampOptions ¶
type StampOptions struct {
// PageRef 是 StampAnnot@PageRef 引用的页面 ID;为空时使用首个文档体的首页。
PageRef string
// Boundary 是 StampAnnot@Boundary,格式为 "x y width height";为空时在首页右下角放置默认大小印章。
Boundary string
}
StampOptions 描述签章在页面上的位置。
Click to show internal directories.
Click to hide internal directories.