e-invoicing

XML signature examples

Sample XML structures showing enveloping, enveloped, cXML, and other signature formats produced by TrustWeaver.

Enveloping signature

An enveloping signature is a signature where the signed document (or, in some cases, the signed fields) will be part of the signature element. The following example shows an enveloping XAdES-T signature.

CODE
<Signature Id="signature" xmlns="http://www.w3.org/2000/09/xmldsig#"> 
  <SignedInfo> 
    <CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315" 
/> 
    <SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /> 
    <Reference URI="#signatureProperties" 
Type="http://www.w3.org/2000/02/xmldsig#SignatureProperties"> 
      <DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> 
      <DigestValue>KcdpJu81a6KFJD2ZZnD36Mh6Uaw=</DigestValue> 
    </Reference> 
    <Reference URI="#SignedContent" Type="http://www.w3.org/2000/09/xmldsig#Object"> 
      <DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /> 
      <DigestValue>g+TT+TvbROIHNi5Tt6eXePIs0g4=</DigestValue> 
    </Reference> 
  </SignedInfo> 
  <SignatureValue>...</SignatureValue> 
  <KeyInfo> 
    <X509Data xmlns="http://www.w3.org/2000/09/xmldsig#"> 
     <X509Certificate>...</X509Certificate> 
    </X509Data> 
  </KeyInfo> 
  <Object> 
    <xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#  
Target="#cXMLSignature"> 
      <xades:SignedProperties Id="XAdESSignedProps"> 
        <xades:SignedSignatureProperties> 
          <xades:SigningTime>...</xades:SigningTime> 
          <xades:SigningCertificate>...</xades:SigningCertificate> 
          <xades:SignaturePolicyIdentifier>...</xades:SignaturePolicyIdentifier> 
        </xades:SignedSignatureProperties> 
      </xades:SignedProperties> 
      <xades:UnsignedProperties> 
        <xades:UnsignedSignatureProperties> 
          <xades:SignatureTimeStamp>...</xades:SignatureTimeStamp> 
        </xades:UnsignedSignatureProperties> 
      </xades:UnsignedProperties> 
    </xades:QualifyingProperties> 
  </ds:Object> 
  <Object Id="SignedContent"> 
    <Doc>...<Doc> 
  </Object> 
</Signature>
Note: For enveloping signatures, multiple signers are not supported.

Enveloped cXML signature for single signer

  • All cXML signatures are enveloped and there can be one or two signatures embedded in cXML.

  • The signatureVersion "1.0" attribute is added to the cXML element.

  • The Request, Response, or Message element is signed in its entirety, identified by the Id="cXMLData" attribute.

  • The Id attribute of the ds:Signature element is set to "cXMLSignature" and the Target attribute of xades:QualifyingProperties is "#cXMLSignature".

  • A ds:Object is added which contains a cXMLSignedInfo element with the Id attribute set to "cXMLSignedInfo" and the values of signatureVersion and payloadID are copied from the same attributes in the cXML element.

  • The following example shows a cXML document with one XAdES-A signature; both XAdES-T and XAdES-A signatures are supported.

  • If XAdES-A is used a ds:Object is added which contains an Extrinsic element with the name attribute set to "ValidationPolicyId". The value for this Extrinsic element is the object identifier for the validation policy. This ds:Object will always be placed after the cXMLSignedInfo ds:Object element.

  • If XAdES-A is used a ds:Object is added which contains a Extrinsic element with the name attribute set to "ValidationPolicyQualifier". The value for this Extrinsic element is the URL to the validation policy. This ds:Object will always be placed after the Extrinsic ds:Object element. See more about ValidationPolicy objects (XAdES-A)

  • Three ds:Reference elements with Algorithm "http://www.w3.org/2000/09/xmldsig#sha1" are added in the following order:
    • URI="#cXMLSignedInfo" ("#cXMLSignedInfo2" if in second signature)

    • URI="#cXMLData"

    • URI="#XAdESSignedProps" ("#XAdESSignedProps2" if in second signature)

  • The ds:KeyInfo of the ds:Signature element contains the signature certificate as a ds:X509Certificate element in the Base 64 DER encoded format.

  • One or two ds:Signature elements are added after the cxml:Request, cxml:Response or cxml:Message element in the cXML document.

XML
<?xml version="1.0" encoding="utf-8"?> 
<!DOCTYPE cXML SYSTEM "InvoiceDetail.dtd"> 
<cXML payloadID="..." signatureVersion="1.0" timestamp="..." version="1.2.011"> 
  <Header>...</Header> 
  <Request Id="cXMLData">...</Request> 
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature"> 
    <ds:SignedInfo> 
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315"> 
      </ds:CanonicalizationMethod> 
      <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"> 
      </ds:SignatureMethod> 
      <ds:Reference URI="#cXMLSignedInfo"></ds:Reference> 
      <ds:Reference URI="#cXMLData"></ds:Reference> 
      <ds:Reference URI="#XAdESSignedProps"></ds:Reference> 
    </ds:SignedInfo> 
    <ds:SignatureValue>...</ds:SignatureValue> 
    <ds:KeyInfo></ds:KeyInfo> 
    <ds:Object> 
      <cXMLSignedInfo Id="cXMLSignedInfo" payloadID="..." signatureVersion="1.0" xmlns="" 
/> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyId">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyQualifier">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#  
Target="#cXMLSignature"> 
        <xades:SignedProperties Id="XAdESSignedProps"> 
          <xades:SignedSignatureProperties> 
            <xades:SigningTime>...</xades:SigningTime> 
            <xades:SigningCertificate>...</xades:SigningCertificate> 
            <xades:SignaturePolicyIdentifier>...</xades:SignaturePolicyIdentifier> 
          </xades:SignedSignatureProperties> 
        </xades:SignedProperties> 
        <xades:UnsignedProperties> 
          <xades:UnsignedSignatureProperties> 
            <xades:SignatureTimeStamp>...</xades:SignatureTimeStamp> 
            <xades:CertificateValues...></xades:CertificateValues> 
            <xades:RevocationValues>...</xades:RevocationValues> 
            <xades:ArchiveTimeStamp>...</xades:ArchiveTimeStamp> 
          </xades:UnsignedSignatureProperties> 
        </xades:UnsignedProperties> 
      </xades:QualifyingProperties> 
    </ds:Object> 
  </ds:Signature> 
</cXML>

Enveloped cXML signature for two signers

When two signatures are present in the same cXML document, the second ds:Signature element uses Id="cXMLSignature2" and corresponding references use the 2 suffix.

XML
<?xml version="1.0" encoding="utf-8"?> 
<!DOCTYPE cXML SYSTEM "InvoiceDetail.dtd"> 
<cXML payloadID="..." signatureVersion="1.0" timestamp="..." version="1.2.011"> 
  <Header>...</Header> 
  <Request Id="cXMLData">...</Request> 
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature"> 
    <ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315"> 
      </ds:CanonicalizationMethod> 
      <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"> 
      </ds:SignatureMethod> 
      <ds:Reference URI="#cXMLSignedInfo"></ds:Reference> 
      <ds:Reference URI="#cXMLData"></ds:Reference> 
      <ds:Reference URI="#XAdESSignedProps"></ds:Reference> 
    </ds:SignedInfo> 
    <ds:SignatureValue>...</ds:SignatureValue> 
    <ds:KeyInfo></ds:KeyInfo> 
    <ds:Object> 
      <cXMLSignedInfo Id="cXMLSignedInfo" payloadID="..." signatureVersion="1.0" xmlns="" 
/> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyId">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyQualifier">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#  
Target="#cXMLSignature"> 
        <xades:SignedProperties Id="XAdESSignedProps">...</xades:SignedProperties> 
        <xades:UnsignedProperties>...</xades:UnsignedProperties> 
      </xades:QualifyingProperties> 
    </ds:Object> 
  </ds:Signature> 
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature2"> 
    <ds:SignedInfo> 
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315"> 
      </ds:CanonicalizationMethod> 
      <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"> 
      </ds:SignatureMethod> 
      <ds:Reference URI="#cXMLSignedInfo2"></ds:Reference> 
      <ds:Reference URI="#cXMLData"></ds:Reference> 
      <ds:Reference URI="#XAdESSignedProps2"></ds:Reference> 
    </ds:SignedInfo> 
    <ds:SignatureValue>...</ds:SignatureValue> 
    <ds:KeyInfo></ds:KeyInfo> 
    <ds:Object> 
      <cXMLSignedInfo Id="cXMLSignedInfo2" payloadID="..." signatureVersion="1.0" 
xmlns="" /> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyId">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <Extrinsic name="ValidationPolicyQualifier">...</Extrinsic> 
    </ds:Object> 
    <ds:Object> 
      <xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#  
Target="#cXMLSignature2"> 
        <xades:SignedProperties Id="XAdESSignedProps2">...</xades:SignedProperties> 
        <xades:UnsignedProperties>...</xades:UnsignedProperties> 
      </xades:QualifyingProperties> 
    </ds:Object> 
  </ds:Signature> 
</cXML>

ValidationPolicy objects (XAdES-A)

When XAdES-A is used, two ds:Object elements carry the validation policy identifier and its URL qualifier.
  • ValidationPolicyId: The validation policy object identifier as a ds:Object element.

  • ValidationPolicyQualifier: The validation policy URL as a ds:Object element.

CODE
<!-- Validation policy OID -->
<ds:Object>
  <Extrinsic name="ValidationPolicyId">
    <xades:Identifier Qualifier="OIDAsURN">urn:oid:1.2.7.76</xades:Identifier>
  </Extrinsic>
</ds:Object>

<!-- Validation policy URL -->
<ds:Object>
  <Extrinsic name="ValidationPolicyQualifier">
    <xades:SPURI>
      http://ts.company.com/ts/rh.ashx?oid=1.2.7.76&amp;doc=validate
    </xades:SPURI>
  </Extrinsic>
</ds:Object>