using IronPdf;using IronPdf.Signing;using IronSoftware.Pdfium.Signing;using System.Drawing;ChromePdfRenderer renderer = new ChromePdfRenderer();PdfDocument pdf = renderer.RenderHtmlAsPdf("<h1>Testing</h1>");// Define Paths and Credentialsstring softhsmLibraryPath = @"D:\SoftHSM2\lib\softhsm2-x64.dll";// These MUST match what you createdstring hsmTokenLabel = "MyTestToken";string hsmPin = "123456";string hsmKeyLabel = "my-key"; // The label for the key *inside* the token// Create the HsmSigner object.UsbPkcs11HsmSigner hsmSigner = new UsbPkcs11HsmSigner( softhsmLibraryPath, hsmPin, hsmTokenLabel, hsmKeyLabel);// Create the Signature Imagestring signatureImagePath = "IronSoftware.png";PdfSignatureImage sigImage = new PdfSignatureImage(signatureImagePath, 0, new Rectangle(50, 50, 150, 150));// Sign PDF with HSMpdf.SignAndSave("signedWithHSM.pdf", hsmSigner);
using IronPdf;
using IronPdf.Signing;
using IronSoftware.Pdfium.Signing;
using System.Drawing;
ChromePdfRenderer renderer = new ChromePdfRenderer();
PdfDocument pdf = renderer.RenderHtmlAsPdf("<h1>Testing</h1>");
// Define Paths and Credentials
string softhsmLibraryPath = @"D:\SoftHSM2\lib\softhsm2-x64.dll";
// These MUST match what you created
string hsmTokenLabel = "MyTestToken";
string hsmPin = "123456";
string hsmKeyLabel = "my-key"; // The label for the key *inside* the token
// Create the HsmSigner object.
UsbPkcs11HsmSigner hsmSigner = new UsbPkcs11HsmSigner(
softhsmLibraryPath,
hsmPin,
hsmTokenLabel,
hsmKeyLabel
);
// Create the Signature Image
string signatureImagePath = "IronSoftware.png";
PdfSignatureImage sigImage = new PdfSignatureImage(signatureImagePath, 0, new Rectangle(50, 50, 150, 150));
// Sign PDF with HSM
pdf.SignAndSave("signedWithHSM.pdf", hsmSigner);
ImportsIronPdfImportsIronPdf.SigningImportsIronSoftware.Pdfium.SigningImportsSystem.DrawingDim renderer As New ChromePdfRenderer()Dim pdf AsPdfDocument = renderer.RenderHtmlAsPdf("<h1>Testing</h1>")' Define Paths and CredentialsDim softhsmLibraryPath AsString = "D:\SoftHSM2\lib\softhsm2-x64.dll"' These MUST match what you createdDim hsmTokenLabel AsString = "MyTestToken"Dim hsmPin AsString = "123456"Dim hsmKeyLabel AsString = "my-key" ' The label for the key *inside* the token' Create the HsmSigner object.Dim hsmSigner As New UsbPkcs11HsmSigner(softhsmLibraryPath, hsmPin, hsmTokenLabel, hsmKeyLabel)' Create the Signature ImageDim signatureImagePath AsString = "IronSoftware.png"Dim sigImage As New PdfSignatureImage(signatureImagePath, 0, New Rectangle(50, 50, 150, 150))' Sign PDF with HSMpdf.SignAndSave("signedWithHSM.pdf", hsmSigner)
Imports IronPdf
Imports IronPdf.Signing
Imports IronSoftware.Pdfium.Signing
Imports System.Drawing
Dim renderer As New ChromePdfRenderer()
Dim pdf As PdfDocument = renderer.RenderHtmlAsPdf("<h1>Testing</h1>")
' Define Paths and Credentials
Dim softhsmLibraryPath As String = "D:\SoftHSM2\lib\softhsm2-x64.dll"
' These MUST match what you created
Dim hsmTokenLabel As String = "MyTestToken"
Dim hsmPin As String = "123456"
Dim hsmKeyLabel As String = "my-key" ' The label for the key *inside* the token
' Create the HsmSigner object.
Dim hsmSigner As New UsbPkcs11HsmSigner(softhsmLibraryPath, hsmPin, hsmTokenLabel, hsmKeyLabel)
' Create the Signature Image
Dim signatureImagePath As String = "IronSoftware.png"
Dim sigImage As New PdfSignatureImage(signatureImagePath, 0, New Rectangle(50, 50, 150, 150))
' Sign PDF with HSM
pdf.SignAndSave("signedWithHSM.pdf", hsmSigner)
// Configure with custom algorithmsvar customHsmSigner = new UsbPkcs11HsmSigner( hsmLibraryPath, hsmPin, hsmTokenLabel, hsmKeyLabel, digestAlgorithm: IronPdf.Signing.DigestAlgorithm.SHA512, signingAlgorithm: IronPdf.Signing.SigningAlgorithm.RSA);// Apply signature with custom location and reasonvar signatureOptions = new SignatureOptions{SignerName = "Corporate Signing Authority",Location = "Company Headquarters",Reason = "Contract Approval"};// Load existing PDF for signingvar existingPdf = PdfDocument.FromFile("contract.pdf");existingPdf.SignAndSave("contract-signed.pdf", customHsmSigner, signatureOptions);
// Configure with custom algorithms
var customHsmSigner = new UsbPkcs11HsmSigner(
hsmLibraryPath,
hsmPin,
hsmTokenLabel,
hsmKeyLabel,
digestAlgorithm: IronPdf.Signing.DigestAlgorithm.SHA512,
signingAlgorithm: IronPdf.Signing.SigningAlgorithm.RSA
);
// Apply signature with custom location and reason
var signatureOptions = new SignatureOptions
{
SignerName = "Corporate Signing Authority",
Location = "Company Headquarters",
Reason = "Contract Approval"
};
// Load existing PDF for signing
var existingPdf = PdfDocument.FromFile("contract.pdf");
existingPdf.SignAndSave("contract-signed.pdf", customHsmSigner, signatureOptions);
ImportsIronPdf' Configure with custom algorithmsDim customHsmSigner As New UsbPkcs11HsmSigner( hsmLibraryPath, hsmPin, hsmTokenLabel, hsmKeyLabel, digestAlgorithm:=IronPdf.Signing.DigestAlgorithm.SHA512, signingAlgorithm:=IronPdf.Signing.SigningAlgorithm.RSA)' Apply signature with custom location and reasonDim signatureOptions As New SignatureOptionsWith { .SignerName = "Corporate Signing Authority", .Location = "Company Headquarters", .Reason = "Contract Approval"}' Load existing PDF for signingDim existingPdf AsPdfDocument = PdfDocument.FromFile("contract.pdf")existingPdf.SignAndSave("contract-signed.pdf", customHsmSigner, signatureOptions)
Imports IronPdf
' Configure with custom algorithms
Dim customHsmSigner As New UsbPkcs11HsmSigner(
hsmLibraryPath,
hsmPin,
hsmTokenLabel,
hsmKeyLabel,
digestAlgorithm:=IronPdf.Signing.DigestAlgorithm.SHA512,
signingAlgorithm:=IronPdf.Signing.SigningAlgorithm.RSA
)
' Apply signature with custom location and reason
Dim signatureOptions As New SignatureOptions With {
.SignerName = "Corporate Signing Authority",
.Location = "Company Headquarters",
.Reason = "Contract Approval"
}
' Load existing PDF for signing
Dim existingPdf As PdfDocument = PdfDocument.FromFile("contract.pdf")
existingPdf.SignAndSave("contract-signed.pdf", customHsmSigner, signatureOptions)
IronPDF 使用 PKCS#11 API 标准进行 HSM 通信,确保与标准 HSM 设备兼容。这种通用的 API 使 IronPDF 能够与各种 HSM 硬件令牌和安全模块无缝交互。
如何验证我的 PDF 已成功使用 HSM 签名?
using IronPDF 的 HSM 功能签署 PDF 后,您可以在任何标准 PDF 查看器中打开已签署的 PDF 来验证签名。查看器将显示数字签名信息,并确认文档的真实性和完整性。
How do I add a trusted timestamp to an HSM-signed PDF?
Set the TimeStampUrl property on the signer to the endpoint of an RFC 3161 Time Stamp Authority before calling SignAndSave. The endpoint is supplied as a string, and the resulting signature carries a timestamp token that readers such as Adobe Acrobat recognize. Leaving the property null or empty skips timestamping entirely and makes no network call.
Which hash algorithm does the HSM timestamp use?
TimestampHashAlgorithm selects the digest requested from the timestamp authority and accepts SHA1, SHA256, or SHA512. The built-in UsbPkcs11HsmSigner defaults to SHA256 through its AHsmSigner base class. A custom signer that implements IHsmSigner directly without deriving from AHsmSigner receives the uninitialized enum value, which is SHA1, so it should set the property explicitly. Note that this is separate from the digestAlgorithm constructor parameter, which governs the signature itself rather than the timestamp.
What causes a TimestampException during HSM signing?
TimestampException is thrown when a timestamp cannot be obtained or embedded. The three causes are an unreachable Time Stamp Authority, an authority that returns an empty token, and a timestamped signature that does not fit the reserved signature space, which can happen when a TSA returns a very large certificate chain. The exception message states the actual size against the reserved size.