e-invoicing

S/MIME example

A sample S/MIME signed message showing the multipart/signed structure and PKCS7 signature attachment produced by TrustWeaver.

TrustWeaver produces a detached S/MIME message of type multipart/signed with the protocol application/pkcs7-signature. The signed document occupies the first MIME part and the PKCS7 signature is attached as smime.p7s in the second part.

Note: TrustWeaver does not canonicalize the input before signing. If necessary, canonicalize the input before calling the Sign method.

The following example shows the complete S/MIME message structure for a signed XML invoice.

CODE
Mime-Version: 1.0
Date: Tue, 04 Oct 2005 13:08:05 +2
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
  micalg=SHA1; boundary="8780c814ed6d409eaf69c8f0064b0444"

--8780c814ed6d409eaf69c8f0064b0444
Content-Type: text/xml; charset="utf-8"

<SAMPLE_INVOICE xmlns="http://www.company.com/Invoice/sample/V4.2.1">
  ...
</SAMPLE_INVOICE>

--8780c814ed6d409eaf69c8f0064b0444
Content-Transfer-Encoding: base64
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Disposition: attachment; filename="smime.p7s"

MIIL2AYJKoZIhvcNAQcCoIILyTCCC8UCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAkqZjixMObw
...
RVrdaSwmScPgJVRYxc2ZzqkduMoEvuP76vSPsZ95CvJ2iDwP2XDPN5uwj+s2dBPbBj2LiyUC8JbaTAH
--8780c814ed6d409eaf69c8f0064b0444--

MIME header handling

When signing with S/MIME, TrustWeaver places all MIME headers that do not start with Content- at the beginning of the resulting S/MIME message. Headers that start with Content- remain as part of the plaintext body. The Mime-Version: 1.0 header is always added to the output.

If the input document has no MIME headers, TrustWeaver assumes Content-Type: text/plain; charset=us-ascii.

Document format requirements

To sign a document with S/MIME, set the document format to OTHER and set InitialContentEncoding to MIME in the request. The input document must include at least a Content-Type MIME header.

Note: The combination of document type EANCOM and signature type SMIME is only valid when InitialContentEncoding is set to MIME. For more details, go to Document and signature format combinations.