XML Signer User Manual

Add a digital signature to your XML documents in a few clicks, sign whole folders automatically, and check signed documents with XML Signer Viewer. No technical knowledge needed; developers find PowerShell, C# and VB.NET examples at the end.

1. What is XML Signer?

An XML document (for example an electronic invoice) can be changed by anyone who has the file. A digital signature solves two problems:

The main function of XML Signer is to sign XML files with X.509 digital certificates. You can sign a single document, or select an input folder and an output folder and sign hundreds of documents at once (bulk signing), which is ideal for the documents of a company. The same signatures can be created automatically, without any window, from the command line (section 12).

The product has two programs:

ProgramWhat it does
XML SignerAdds digital signatures to one XML document or to a whole folder of documents. Works from the window or from the command line.
XML Signer ViewerOpens a signed XML document and tells you who signed it, when, and whether the signature is still valid.
Your document is not rewritten

The signature is added inside the XML file. The original content stays exactly as it was. The signed copy is saved in the destination you choose, so your original file is never lost.

Who is this manual for?

Useful links

WhatAddress
XML Signer product page (information, purchase, download)https://www.signfiles.com/xml-signer/
Download XML Signer (free trial)https://www.signfiles.com/apps/XMLSigner.msi
Signature Library (SignLib) used by XML Signerhttps://www.signfiles.com/signature-library/
Signature Library code sampleshttps://www.signfiles.com/code-samples/
Support and contacthttps://www.signfiles.com/contact/

2. Product installation

We recommend installing the product with an Administrator account. After the setup file is verified, the operating system might ask for your permission to install the program: click Yes.

What you need

Installation steps

  1. Download the setup file. Get XMLSigner.msi from the product page and run it.
  2. If Windows SmartScreen appears, allow the program to run. You may see the window Windows protected your PC. Click More info and then Run anyway. See the explanation below.
  3. Read the license agreement. Read the EULA (End-User License Agreement). If you want to continue, select I Agree and click Next until the setup is finished.
  4. Start the program. The setup installs XML Signer and XML Signer Viewer. Start them from the Windows Start menu. By default the files are in the Secure Soft\XML Signer folder of Program Files (on a 64-bit Windows: C:\Program Files (x86)\Secure Soft\XML Signer).
License Agreement page of the setup
The license agreement page of the setup. Select I Agree to enable the Next button.

What is Windows SmartScreen?

SmartScreen is a protection built into Windows. When you run a program you downloaded, Windows compares it with a list of programs that are known and were already downloaded by many people. A program that Windows does not know yet, for example a new version that was published recently, is shown as an unrecognized app, and the window below appears.

Windows SmartScreen: Windows protected your PC
The SmartScreen message. The text and the colors change a little between Windows versions, but the two steps are the same: More info, then Run anyway.

This message does not mean that the file contains a virus. It only means that Windows has no reputation data about it yet. To continue:

  1. Click More info. The name of the file and of the publisher are displayed.
  2. Click Run anyway and the setup starts.
Do it only for files you trust

Run the setup only if you downloaded it from www.signfiles.com. If you prefer, you can also right-click the downloaded XMLSigner.msi, choose Properties, tick Unblock (at the bottom of the General tab) and click OK. The setup then starts without the SmartScreen message.

3. Trial period and product registration

A new, unregistered installation works for a trial period of about 30 days. The title of the window shows how much is left, for example XML Signer - Expires in 30 days, and the buttons Register Now and Buy Now! are visible.

XML Signer in the trial period
The trial version: the title shows the remaining days, and the Buy Now! and Register Now buttons are visible.

How to register the product

  1. Get a serial number. To register the product you need a serial number (also called license code). You can buy it online directly from the product page, https://www.signfiles.com/xml-signer/. You can also click Buy Now! in the program, which opens the same page.
  2. Open the registration window. Open XML Signer and click the Register Now button (or Help → Register Now...).
  3. Type the license code. Enter the received serial in the first box. The second box, Licensed to (optional), is for a name: if you type one, it is shown in the title of the window.
  4. Click Register. If the serial number is correct, the product is successfully registered.
The Registration window
The Registration window. The code in this picture is only an example.
Message: XML Signer was registered successfully
The message you see after a successful registration.
XML Signer after the registration
After registration the title changes to Registered to and your name (or Registered version if you did not type a name), and the buy buttons disappear.
Good to know
  • The license code has 20 characters (letters and digits). Type it exactly as you received it. The messages License code cannot be empty. and Invalid license code. mean that the box is empty, or that the code was mistyped.
  • The registration is saved for the Windows user account that registered the program. If another person uses the same computer with a different account, the registration is done once more with the same code.
  • XML Signer Viewer is installed together with XML Signer and has no registration window.
After the trial ends

When the trial has expired, the title shows Expired on and a date, and XML Signer no longer signs documents until you register.

4. Sign your first document

This is the whole process. It takes less than a minute once you have a certificate.

XML Signer main window at first start
The main window when you start the program for the first time.
  1. Choose the document. Keep A single XML document selected. Click the ... button under Source and select the XML file you want to sign.
  2. Choose where to save the signed copy. Click the ... button under Destination and pick a folder and a file name (for example invoice-001-signed.xml). The destination must be a different file from the source.
  3. Select your digital certificate. Click Select the Digital Certificate.... Choose the certificate from the Windows store, or a .pfx file, and click OK (details in section 6).
  4. Leave the format on the recommended value. XAdES-B-B - basic (recommended) and SHA256 are already selected and are the right choice for most uses (see section 7).
  5. Click Apply Digital Signature. After a moment you see the message The file was digitally signed succesfully. Your signed document is in the destination you chose.
XML Signer with source, destination and certificate selected
Ready to sign: source, destination and certificate are set. The line above Apply Digital Signature shows which certificate will be used (here, Elaine Smith, a PFX file).
Message: The file was digitally signed successfully
The confirmation message.
Tip: start the program with a file already chosen

Drag a file onto the program icon, or right-click an XML file and choose Open with → XML Signer. The file is selected as the source automatically.

5. The main window

ItemWhat it does
Digitally signChoose A single XML document or A folder with XML documents (all .xml files of the folder are signed).
SourceThe document (or folder) you want to sign. Use the ... button to browse.
DestinationWhere the signed document (or the signed documents) will be saved.
Signature FormatThe kind of signature to create. The default, XAdES-B-B - basic, is the right choice for normal use. See section 7.
Hash AlgorithmThe mathematical fingerprint used to detect changes: SHA256 (default), SHA384 or SHA512. Keep SHA256 unless the party receiving your documents asks for another one. The older SHA1 is not supported.
CanonicalizationOnly used for the XMLDSig format (the box is grayed out for XAdES). It tells the program how to normalize the XML before signing. Keep Default unless you were told to use another value.
Select the Digital Certificate...Opens the certificate window (section 6). Below this button you always see which certificate is currently selected and until when it is valid.
Time Stamp Settings...Available only for the formats that use a time stamp (XAdES-B-T, -LT and -LTA). See section 8.
Apply Digital SignatureSigns the document or the folder. While a folder is being signed you can stop it with the Cancel button in the bottom bar; the bar also shows the progress.

Menus

MenuCommands
FileOpen (choose a document or folder), Apply Digital Signature..., Save Configuration, Save Configuration As..., Load Configuration..., Exit.
ToolsSelect the Digital Certificate..., Time Stamp Settings..., Create a self-signed Digital Certificate..., Restore Defaults (asks you to confirm, then sets all options back to their original values).
HelpAbout... (program version and registration status) and Register Now... (only while the program is not registered).

6. Digital certificates

A digital certificate is your electronic identity card, issued by a certification authority. To sign with XML Signer you need one. This section explains where certificates are kept and how to select the one you want to sign with.

6.1 Where the certificates are stored

A certificate that can sign documents has two parts: a public key (the part other people see, inside the certificate) and a private key (the secret part, which only you have). The digital signature is created with the private key. The certificates are kept in two places:

The Windows Certificate Store (Microsoft Store)

The Windows Certificate Store is the place where Windows keeps the certificates of the computer and of each user. In XML Signer it appears as Windows Certificate Store and Certificates Available on Microsoft Store.

Not the Microsoft Store of applications

The certificate store has nothing to do with the Microsoft Store where you download applications. It is only the traditional name of the list of certificates of Windows.

To see the certificates of your account:

  1. Press Win + R, type certmgr.msc and press Enter.
  2. Open Personal → Certificates.

(The older way still works: Internet Options → Content tab → Certificates button, tab Personal.)

To create digital signatures, the certificates of the Personal store are used. They must have a public and a private key. You can check this by opening a certificate: in the General tab Windows writes You have a private key that corresponds to this certificate.

Windows certificate window with the private key message
A certificate opened with Windows. The line at the bottom shows that the private key is available on this computer. The Show buttons of XML Signer open this same window.

The private key itself can be stored:

The certificates you can use are listed per store location: Current User (your own certificates, the usual case) or Local Machine (certificates installed for all the users of the computer).

PFX and P12 files

Another way to keep a digital certificate is a PFX (or P12) file. The file contains the public and the private key of the certificate, and it is protected by a password, to keep the key pair safe.

Importing a PFX into the Windows store

A PFX/P12 file can be imported into the Windows Certificate Store: just open the file (double-click it) and follow the Certificate Import Wizard. After that, the certificate is available in the Personal list and you can select it from the Windows store without the file.

6.2 Certificates stored on smart cards or USB tokens

If your certificate is stored on a smart card or on a USB token (like Aladdin eToken or SafeNet), the private key never leaves the device: it signs inside the device. For XML Signer to use it, the certificate must appear in the Windows Certificate Store (6.1).

Usually, the driver of the smart card or its middleware (the software delivered with the token) installs the certificate in the Windows store automatically when the token is connected. If the certificate does not appear in the list, ask your vendor how to add it to the store, and look at the options of the middleware, like below:

Middleware option Copy user certificates to a local store
In the settings of the middleware, the option that copies the certificates of the token to the Windows store (here: Copy user certificates to a local store).
Middleware button Registration
Some middleware tools have a Registration button that adds the selected certificate to the Microsoft Certificate Store.

Once the certificate is in the store, select it in XML Signer as described in 6.3.

Certificate on a smart card selected in XML Signer
A certificate kept on a smart card. Certificate Information shows the name of the provider of the key (here SafeNet Smart Card Key Storage Provider), which tells you that the key is on a card. The Smart Card PIN box is ticked.
The smart card PIN

Normally Windows asks for the PIN of the card every time you sign. If you do not want the PIN window (for example for batch signatures, section 12), tick Smart Card PIN and type the PIN. The PIN is saved encrypted in the configuration, it belongs to the selected certificate, and it is cleared when you select another certificate. If the card rejects the PIN, XML Signer stops using it (so your card does not get locked by repeated wrong attempts): correct it in this window and try again.

6.3 Select the digital certificate for creating signatures

To digitally sign a document, a digital certificate must be selected first. Click Select the Digital Certificate... (or Tools → Select the Digital Certificate...). The certificate can be stored in the Windows store or in a PFX file.

Digital Certificates window with the PFX option selected
The Digital Certificates window with a PFX file selected. (The list of certificates of the Windows store is hidden in this picture.) The Certificate Information box confirms that the file and the password are correct.

Option A: a PFX file

Some certificates are delivered as a file with the extension .pfx (or .p12), protected by a password.

  1. Select PFX digital certificate file.
  2. Click ... and pick your .pfx file (or type its path).
  3. Type the PFX file password. The Show button next to it displays the details of the certificate so you can check you picked the right one.
  4. Click OK.

Option B: a certificate installed in Windows

Certificates installed on the computer, or stored on a USB token or smart card, appear in the Windows Certificate Store.

Digital Certificates window with the Windows Certificate Store option
A certificate selected from the Windows Certificate Store.
  1. Select Windows Certificate Store.
  2. In Certificate Store choose Current User (your own certificates, the usual case) or Local Machine (certificates installed for the whole computer).
  3. Pick your certificate from the list Certificates Available on Microsoft Store. The list shows the name of the owner, the issuer and the expiry date; an expired certificate is marked EXPIRED and is placed at the end. Show displays the full certificate.
  4. Click OK.

Certificate Information

At the bottom of the window, Certificate Information summarizes the selected certificate: to whom and by whom it was issued, until when it is valid, and Certificate Service Provider. The last one is the name of the software (or of the device driver) that manages the private key of the certificate. It helps you understand where the key is:

Provider shownWhere the private key is
Microsoft Software Key Storage Provider, Microsoft Enhanced Cryptographic ProviderIn your Windows account, on the computer (for example an imported PFX file).
eToken Base Cryptographic Provider, SafeNet Smart Card Key Storage Provider or similar names from the token vendorOn a smart card or USB token. A PIN is needed to sign.

(The abbreviations are CSP, Cryptographic Service Provider, for the classic providers, and KSP, Key Storage Provider, for the newer ones. You do not have to choose them: XML Signer uses the provider of the certificate.) If the private key is not available on this computer, the line The private key is not available is added.

Long-term validation data

At the bottom of the window, Revocation data of the XAdES-LT and XAdES-LTA signatures chooses what proof of validity is saved inside those signatures (see section 7):

The button Create a self-signed Certificate... at the bottom left is explained in section 9.

Expired certificates cannot sign

If the certificate is expired or not valid yet, or its private key is missing, XML Signer refuses to sign and explains why. Renew the certificate or choose another one.

7. Signature formats

The format decides how much information is stored inside the signature. If you are not sure, keep the first one.

Format in the listWhat it addsWhen to use it
XAdES-B-B — basic recommendedThe signature and the signer's certificate.Everyday use: invoices, contracts, exchanged documents. Works offline and needs no extra settings.
XAdES-B-T — with time-stampA trusted time stamp from an independent server that proves the exact time of signing.When you must prove when the document was signed. Needs an Internet connection (see section 8).
XAdES-B-LT — long term validationTime stamp plus the certificates and revocation proofs (OCSP/CRL) of the signer.Documents that must stay verifiable for years, even after the certificate expires or the issuer's servers are gone.
XAdES-B-LTA — long term archivalEverything from LT plus an archive time stamp.Archives that must remain provable for many years.
XMLDSig — old standardA basic signature in the older, general format.Only when the receiving system specifically asks for plain XMLDSig. It has the extra Canonicalization option.
Main window with the XMLDSig format selected
With XMLDSig selected, the Canonicalization list becomes available (it is grayed out for XAdES formats).

XAdES is the European standard for advanced electronic signatures. The letters B, T, LT and LTA come from the standard: Basic, Time-stamp, Long Term and Long Term Archival.

8. Time stamp settings

A time stamp is issued by a Time Stamp Authority (TSA), an independent service. It proves that your signature existed at a given moment and cannot be back-dated. It is used by XAdES-B-T, -LT and -LTA. Open it with Time Stamp Settings....

Time Stamping window
The Time Stamping window.
SettingMeaning
Time Stamp Server URLThe web address of the TSA service. The program starts with https://ca.signfiles.com/TSAServer.aspx. Use the address given by your provider if you have your own.
Time Stamp Server requires authenticationTick it and type the Username and Password if your provider requires them.
Time Stamp Server PolicyTick it only if your provider asked you to send a policy identifier, and type it.
Use NONCEA random number that protects the request from being replayed. Leave it ticked.
Hash algorithm used for requestSHA256 by default.
Restore DefaultsPuts all these values back to the original ones.
Internet required

The computer must be able to reach the time stamp server while signing. If the address is not valid, XML Signer tells you to set it here before signing.

9. Creating a test certificate

If you do not have a certificate yet and only want to try the program, XML Signer can create a self-signed one. Open Tools → Create a self-signed Digital Certificate... (or the button in the certificate window).

Create a self-signed Digital Certificate window
Filling in the details of a new self-signed certificate.
  1. Choose where to save it: On Microsoft Certificate Store or On a password protected PKCS#12 PFX file (you will be asked for the file name and a password).
  2. Type Issued to (your name, required) and, if you wish, the organization, unit, title, e-mail address and country code.
  3. Choose the Validity period (default 3 years), the RSA Key Algorithm length (default 2048 bits) and the Signature Algorithm (default SHA256WithRSA). The defaults are fine.
  4. Keep Set as current digital certificate ticked to use it right away, then click OK.
For tests only

Nobody except you trusts a self-signed certificate. Other people's programs will show that the signer is unknown. For real documents, use a certificate issued by a recognised certification authority.

10. Signing a whole folder

To sign many documents at once, select A folder with XML documents.

Main window in folder mode
Folder mode: Source and Destination are now folders.
  1. Under Source choose the folder with your XML documents.
  2. Under Destination choose another folder. Each .xml file of the source folder is signed and saved with the same name in the destination folder. The source and the destination must be different folders.
  3. Click Apply Digital Signature. When it finishes you see how many documents were signed.
Message: 3 of 3 XML documents were digitally signed
All three documents of the folder were signed.
Nothing is overwritten by surprise

If files with the same names already exist in the destination, the program asks you first: Would you like to overwrite the existing file? (or, for a folder, how many documents will be overwritten). If a folder contains no XML documents you are told: The selected folder does not contain XML documents.

11. Saving your settings

The program remembers your choices (certificate, format, hash algorithm, time stamp server...) the next time you start it. You can also keep several sets of settings in files — for example one for invoices and one for contracts:

A saved configuration file is also what the command line uses to sign documents automatically.

12. Batch signatures (automatically made without user intervention)

XML Signer can also sign without showing its window, for example from a scheduled task, from a script or from another program. Nobody has to click anything: the program reads the settings from a configuration file, signs, and closes.

By default, XML Signer is installed in the folder C:\Program Files (x86)\Secure Soft\XML Signer (on a 32-bit Windows: C:\Program Files\Secure Soft\XML Signer) and the program is XML Signer.exe.

Command line parameters

"XML Signer.exe" <source file> <destination file | destination folder> [<configuration file>]
"XML Signer.exe" <source folder> <destination folder> [<configuration file>]
"XML Signer.exe" <XML file | folder>      (opens the window with the file or folder selected)
"XML Signer.exe" /?                      (shows this help)

Sign one file

To automatically sign a file, use a command like this one:

c:\Program Files (x86)\Secure Soft\XML Signer>"XML Signer.exe" c:\TestFile.xml "c:\TestFile[signed].xml"

Sign a folder

To automatically sign all the files of a folder:

c:\Program Files (x86)\Secure Soft\XML Signer>"XML Signer.exe" c:\InputFolder c:\OutputFolder

Custom configuration

In some cases you need a different signature configuration (for example a different certificate or signature format) for different files or folders. To save a specific configuration, open the window, set everything you want, and go to File → Save Configuration As... Save the configuration in a file. Later you can use that file in batch mode to apply a different signature configuration on the signed files.

To automatically sign a folder using a custom configuration:

"XML Signer.exe" c:\InputFolder c:\OutputFolder c:\config-client2.xml
No window means no questions

Because nobody is there to answer, choose a certificate that does not need any interaction: a PFX file (its password is saved in the configuration, encrypted) or a smart card certificate with the Smart Card PIN saved (section 6.2). The smart card must be connected. The certificate must be valid: an expired certificate stops the signing, with the result code 2.

Result codes

CodeMeaning
0Success.
1The signing failed (for a folder: at least one file failed).
2The signing could not start: invalid arguments or configuration, the certificate is not valid, or XML Signer is not registered.

XML Signer is a Windows application, so the command prompt does not wait for it. To wait and read the result code:

cmd:         start "" /wait "XML Signer.exe" C:\Demo\Invoices C:\Demo\Signed C:\Demo\invoices.config
             echo %errorlevel%

PowerShell:  (Start-Process "XML Signer.exe" -ArgumentList '"C:\Demo\Invoices" "C:\Demo\Signed" "C:\Demo\invoices.config"' -Wait -PassThru).ExitCode

Log files

Every file signed from the command line is recorded in log.txt, and every error in errorlog.txt. Both are in your user profile, in the folder %APPDATA%\Secure Soft\XML Signer\<version> (the last part is a folder named after the version of the program). The error messages are also written in the command window.

Run it every night

Set up everything once in the window, use Save Configuration As..., and then create a task in the Windows Task Scheduler that starts XML Signer.exe with the source folder, the destination folder and the configuration file. Use the same Windows account for the task that you used to set up the certificate and the registration.

13. XML Signer Viewer

XML Signer Viewer is the second program of the product. Use it to check a signed document you created or received.

Opening a document

Start XML Signer Viewer, click ... next to Source XML file and pick the signed file. You can also right-click a file and choose Open with → XML Signer Viewer.

XML Signer Viewer showing a valid signature
A valid signature: the signer, the format, the signing date and the results are listed.

What you see

LineMeaning
Signers listEvery person who signed the document, numbered. Choose one to see the details below. A document can be signed by several people.
Issuer nameThe certification authority that issued the signer's certificate.
Subject nameThe owner of the certificate, that is, the signer.
Signature formatFor example XAdES-B-B (see section 7).
Signing dateWhen the document was signed. The note (declared by the signer) means it comes from the signer's own computer clock. A trusted time appears only when the signature has a time stamp.
Signature algorithmThe technique used, for example RSA-SHA256.
Certificate statusCertificate is valid, or Certificate is not valid with the reason (for example expired).
Signature integrityThe most important line. The XML signature is valid means the document is exactly as it was when signed. The XML signature is not valid means it was changed or the signature is damaged.
Signature time stamp, Archive time stamps, Validation dataShown for the T, LT and LTA formats: who issued the time stamp and whether it matches the signature, and how many certificates and OCSP/CRL proofs are stored inside.

A document that was changed

If somebody changes the document after it was signed (here, the amount in an invoice), the Viewer says so clearly:

XML Signer Viewer showing an invalid signature
The same file after one number was edited: the signature is reported as not valid.
Do not trust a document whose signature is not valid

Ask the sender for the original signed file.

Buttons

Windows certificate window opened from the Viewer
The certificate window opened with Show certificate.
Valid does not always mean trusted

The Viewer checks that the document was not changed and that the certificate is valid. Whether you trust the signer is your decision: check the Issuer name and the Subject name. A self-signed test certificate shows the same name for both.

14. The Signature Library behind XML Signer

XML Signer is an application built on the Signature Library (SignLib), a library for .NET that creates and verifies digital signatures: PDF (PAdES), CAdES / PKCS#7, XML (XAdES), Office and more. Everything XML Signer does is available to your own programs and scripts through the library:

The library works with Windows PowerShell, C#, VB.NET and ASP.NET, on .NET Framework and on the recent .NET versions, and it supports certificates from PFX files, from the Windows store and from smart cards, USB tokens and HSMs.

One of the purposes of XML Signer

XML Signer is also a demonstration of the library. Before you write any code, use the window to try a signature format, a hash algorithm, a time stamp server or a certificate, and save the result of your test. Every choice you make in the window is one property of the library (see the table below), and the signed file you get is exactly what your code will produce. The XML Signer Viewer shows you how a signature created by your code looks to the people who receive it.

From the window to the code

XAdES signatures are created with the class SignLib.Xml.XadesSignature. The table shows what each setting of XML Signer is in the library.

In XML SignerIn the library
Signature Format: XAdES-B-B, -B-T, -B-LT, -B-LTA (section 7)signature.SignatureStandard = XadesSignatureStandard.XadesB (or XadesT, XadesLT, XadesLTA)
Hash Algorithmsignature.HashAlgorithm = HashAlgorithm.SHA256 (or SHA384, SHA512)
Digital certificate from a PFX fileDigitalCertificate.LoadCertificate(pfxFile, password)
Digital certificate from the Windows store or a smart cardDigitalCertificate.LoadCertificate(...) with a search criterion, or without parameters to show the selection window
Smart Card PINDigitalCertificate.SmartCardPin = "..."
Time Stamp Server URL, user name, password, policy, NONCE, hash (section 8)signature.TimeStamping.ServerUrl, .UserName, .Password, .PolicyOid, .UseNonce, .HashAlgorithm
Revocation data of the LT and LTA signaturessignature.LtvLevel = XadesLtvLevel.IncludeOcspOnly (or IncludeCrl, IncludeCrlAndOcsp, None)
Maximum size of a CRL (in kilobytes in the window)signature.MaxCrlSize (in bytes in the code)
Apply Digital Signaturesignature.ApplyDigitalSignature(inputFile, outputFile)
Create a self-signed certificate (section 9)the class X509CertificateGenerator
XML Signer Viewer (section 13)GetNumberOfSignatures, VerifyDigitalSignature, GetDigitalSignatureCertificate, GetSignatureAlgorithm

The library can do more than the window: detached signatures for files of any type, several signers, the place and the commitment of the signature, an explicit signature policy and the renewal of archive time stamps. They are shown in section 16.

15. Digitally sign XML files using Windows PowerShell

The main functions of XML Signer are available in the SignLib library, which you can download from this link: https://www.signfiles.com/sdk/SignatureLibrary.zip

To digitally sign an XML file using Windows PowerShell, simply download the library above and inspect the Signature Library\PowerShell Scripts folder. There you find ready-made scripts for the other kinds of documents; the script below does the same for XML, using the XAdES signature of XML Signer.

The script

Save it as signXmlDocument.ps1, in the same folder with SignLib.dll. It creates a test PFX certificate on the fly, signs the file in the XAdES-B-B format (SHA256) and verifies the result.

#digitally sign an XML file in the XAdES format, using a PFX certificate created on the fly
#the script can be configured to use an existing PFX file or a certificate loaded from Microsoft Store (smart card certificate)

if ($args.Length -eq 0)
{
    echo "Usage: signXmlDocument.ps1 <unsigned file> <signed file>"
}
else
{
    #SignLib.dll must be on the same folder as the script (or write its full path)
    $DllPath = Join-Path $PSScriptRoot 'SignLib.dll'
    [System.Reflection.Assembly]::LoadFrom($DllPath) | Out-Null

    #create a PFX digital certificate
    $generator = new-object -typeName SignLib.Certificates.X509CertificateGenerator("serial number")
    $pFXFilePassword = "tempP@ssword"
    $generator.Subject = "CN=Your Certificate, E=useremail@email.com, O=Organization"
    $generator.Extensions.AddKeyUsage([SignLib.Certificates.CertificateKeyUsage]::DigitalSignature)
    $generator.Extensions.AddEnhancedKeyUsage([SignLib.Certificates.CertificateEnhancedKeyUsage]::DocumentSigning)

    echo "Create the certificate..."
    $certificate = $generator.GenerateCertificate($pFXFilePassword)

    #digitally sign the file in XAdES format (XAdES-B-B, SHA256)
    $sign = new-object -typeName SignLib.Xml.XadesSignature("serial number")
    $sign.DigitalSignatureCertificate = [SignLib.Certificates.DigitalCertificate]::LoadCertificate($certificate, $pFXFilePassword)

    echo "Perform the digital signature..."
    $sign.ApplyDigitalSignature($args[0], $args[1])

    #verify the signature
    echo ("Signatures: " + $sign.GetNumberOfSignatures($args[1]))
    echo ("Valid: " + $sign.VerifyDigitalSignature($args[1]))
}

How to run it

How to run the Windows PowerShell script from the command line:

powershell -executionPolicy bypass -file d:\signXmlDocument.ps1 d:\test.xml "d:\test[signed].xml"

The result in the window:

Create the certificate...
Perform the digital signature...
Signatures: 1
Valid: True
Good to know
  • Replace "serial number" with the serial number you received for the library. Without it the library works in demonstration mode: it writes This is a demonstration of the digital signature software and waits 10 seconds before every operation.
  • -executionPolicy bypass allows this one script to run without changing the security settings of the computer.
  • To sign with an existing PFX file, remove the certificate generator and use [SignLib.Certificates.DigitalCertificate]::LoadCertificate("d:\certificate.pfx", "password"). For a smart card certificate from the Windows store use the methods described in section 16.

16. Digitally sign XML files using C# or VB.NET

The main functions of XML Signer are available in the SignLib library (download). To digitally sign a file using C# or VB.NET, download the library, add a reference to SignLib.dll in your project, and inspect the sample projects of the package and the code samples page.

XML documents are signed with the class XadesSignature (namespace SignLib.Xml). It creates XAdES signatures, the European standard for advanced electronic signatures, at the four baseline levels B-B, B-T, B-LT and B-LTA (section 7), and verifies them.

All the examples below use these namespaces. Every example was run with the library to check the result.

using SignLib;                 // HashAlgorithm
using SignLib.Certificates;    // DigitalCertificate
using SignLib.Timestamping;    // time stamp settings
using SignLib.Xml;             // XadesSignature and its options

16.1 Sign an XML document and verify the signature

The smallest program: load a certificate from a PFX file, sign, and verify. The signature format is XAdES-B-B and the hash is SHA256, exactly like the defaults of XML Signer.

using SignLib;
using SignLib.Certificates;
using SignLib.Xml;

// "serial number" is the serial number of the library
XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");

// apply the digital signature: the input file is not changed, the signed copy is saved in the output file
signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");

// verify the signature
XadesSignature verifier = new XadesSignature("serial number");
Console.WriteLine("Signatures: " + verifier.GetNumberOfSignatures("invoice-signed.xml"));
Console.WriteLine("Valid: " + verifier.VerifyDigitalSignature("invoice-signed.xml"));
Console.WriteLine("Signer: " + verifier.GetDigitalSignatureCertificate("invoice-signed.xml").Subject);
Console.WriteLine("Algorithm: " + verifier.GetSignatureAlgorithm("invoice-signed.xml"));

The result:

Signatures: 1
Valid: True
Signer: CN=Elaine Smith, O=Demo Company, C=US
Algorithm: RSA-SHA256

The same example in VB.NET:

Imports SignLib
Imports SignLib.Certificates
Imports SignLib.Xml

Module Module1
    Sub Main()
        Dim signature As New XadesSignature("serial number")
        signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate("d:\certificate.pfx", "123456")
        signature.SignatureStandard = XadesSignatureStandard.XadesB
        signature.HashAlgorithm = HashAlgorithm.SHA256

        'apply the digital signature
        signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml")

        Dim verifier As New XadesSignature("serial number")
        Console.WriteLine("Signatures: " & verifier.GetNumberOfSignatures("invoice-signed.xml"))
        Console.WriteLine("Valid: " & verifier.VerifyDigitalSignature("invoice-signed.xml"))
    End Sub
End Module

16.2 Signature levels, time stamp and long-term validation

The level of the signature is chosen with SignatureStandard. The levels that contain a time stamp (XadesT, XadesLT, XadesLTA) need the address of a time stamp server (section 8).

XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");

signature.HashAlgorithm = HashAlgorithm.SHA384;                        // SHA256 (default), SHA384 or SHA512
signature.SignatureStandard = XadesSignatureStandard.XadesLT;          // XadesB, XadesT, XadesLT or XadesLTA
signature.TimeStamping.ServerUrl = new Uri("https://ca.signfiles.com/TSAServer.aspx");
signature.LtvLevel = XadesLtvLevel.IncludeOcspOnly;                    // the revocation data saved in the LT and LTA signatures

signature.ApplyDigitalSignature("invoice.xml", "invoice-lt.xml");

If the time stamp server asks for authentication, or you want to set other options of the request, use the other properties of TimeStamping:

signature.TimeStamping.UserName = "user";                  // only if the server requires authentication
signature.TimeStamping.Password = "password";
signature.TimeStamping.UseNonce = true;                    // a random number that protects the request
signature.TimeStamping.HashAlgorithm = HashAlgorithm.SHA256;
signature.MaxCrlSize = 2 * 1024 * 1024;                    // the largest CRL that is included, in bytes (default: 1 MB)

Renewing the archive time stamp (XAdES-B-LTA)

A XAdES-B-LTA signature is made to be kept for many years. After some time, add a new archive time stamp, before the certificate of the time stamp server expires. The signing certificate is not needed for this.

XadesSignature archive = new XadesSignature("serial number");
archive.TimeStamping.ServerUrl = new Uri("https://ca.signfiles.com/TSAServer.aspx");
archive.AddArchiveTimestamp("invoice-lta.xml", "invoice-lta-renewed.xml");

16.3 A certificate from the Windows store or a smart card

When the certificate is in the Windows store (for instance, a smart card certificate, section 6.2), load it with a search criterion. No window is shown, so the code can run without a user.

XadesSignature signature = new XadesSignature("serial number");

// the first certificate of the current user whose common name (CN) is "Elaine Smith"
// true = only the valid certificates (issued by a trusted authority); false = any certificate, also a self-signed test one
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(true, DigitalCertificateSearchCriteria.CommonNameCN, "Elaine Smith");

// the PIN of the smart card, to avoid the PIN window. It applies to the next signature, made on this thread
DigitalCertificate.SmartCardPin = "1234";

signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");

Other search criteria are the other fields of the subject (OrganizationO, EmailE...), the thumbprint and the serial number of the certificate. To let the user choose the certificate in a Windows window, call DigitalCertificate.LoadCertificate() without parameters.

16.4 Detached signatures: sign a file of any type

By default the signature is added inside the XML document (enveloped). With a detached signature the signature is a separate XML file that refers to the signed file. The signed file can be of any type (PDF, DOCX, ZIP...) and it is not changed. The original file is needed to verify the signature.

XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");
signature.SignaturePackaging = XadesSignaturePackaging.Detached;

signature.ApplyDigitalSignature("contract.pdf", "contract.pdf.xml");

// verify: the signature file and the signed file
XadesSignature verifier = new XadesSignature("serial number");
bool valid = verifier.VerifyDigitalSignature("contract.pdf.xml", "contract.pdf");   // False if contract.pdf was changed

16.5 Several signatures in the same document

A document can have several parallel signatures: a new signature does not invalidate the existing ones. Sign the already signed file again, then check each signature. The index of the signatures starts at 0.

XadesSignature first = new XadesSignature("serial number");
first.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\manager.pfx", "123456");
first.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");

XadesSignature second = new XadesSignature("serial number");
second.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\accountant.pfx", "123456");
second.ApplyDigitalSignature("invoice-signed.xml", "invoice-signed.xml");      // the output can be the input file

XadesSignature verifier = new XadesSignature("serial number");
int count = verifier.GetNumberOfSignatures("invoice-signed.xml");
for (int i = 0; i < count; i++)
    Console.WriteLine("Signature " + (i + 1) + ": " + verifier.VerifyDigitalSignature("invoice-signed.xml", i) + ", signer: "
        + verifier.GetDigitalSignatureCertificate("invoice-signed.xml", i).GetNameInfo(X509NameType.SimpleName, false));

(X509NameType is in the namespace System.Security.Cryptography.X509Certificates.)

A changed document

If the document is modified after the signature, the verification returns False. For example, after the total of an invoice is edited from 1250.00 to 9250.00:

Console.WriteLine("Valid: " + new XadesSignature("serial number").VerifyDigitalSignature("invoice-changed.xml"));
// Valid: False

16.6 More options of the signature

These options are not in the window of XML Signer. They add information to the signature when a regulation or the receiver requires it.

// the commitment declared by the signer: approval, origin, receipt...
signature.CommitmentType = XadesCommitmentType.ProofOfApproval;

// the place where the signature was created
signature.SignatureProductionPlace = new XadesProductionPlace { City = "Bucharest", CountryName = "Romania" };

// an explicit signature policy: identifier (OID or URI), digest of the policy document, the algorithm of the digest, the address of the policy
signature.SetSignaturePolicyInformation("2.16.724.1.3.1.1.2.1.9", policyHash, "SHA256", "https://example.com/policy.pdf");

16.7 How the signature looks

The signature is added at the end of the XML document. The values below are shortened. SigningTime, the certificate of the signer (SigningCertificateV2) and the format of the signed data are the signed XAdES properties; a time stamp (XAdES-B-T and above) is added as an additional property of the signature.

<Invoice>
  <Number>INV-2026-001</Number>
  <Customer>Demo Company</Customer>
  <Total currency="EUR">1250.00</Total>
  <Signature Id="Signature-97744c13a070b011" xmlns="http://www.w3.org/2000/09/xmldsig#">
    <SignedInfo>
      <CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
      <SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
      <Reference Id="r-97744c13a070b011-1" URI="">           <!-- the document -->
        ...
        <DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
        <DigestValue>jakNhmN0...</DigestValue>
      </Reference>
      <Reference URI="#SignedProperties-97744c13a070b011" Type="http://uri.etsi.org/01903#SignedProperties">
        ...                                                   <!-- the XAdES properties -->
      </Reference>
    </SignedInfo>
    <SignatureValue>4Wg+fhw5jb23...</SignatureValue>
    <KeyInfo><X509Data><X509Certificate>MIIDCzCC...</X509Certificate></X509Data></KeyInfo>
    <Object>
      <xades:QualifyingProperties Target="#Signature-97744c13a070b011" xmlns:xades="http://uri.etsi.org/01903/v1.3.2#">
        <xades:SignedProperties Id="SignedProperties-97744c13a070b011">
          <xades:SignedSignatureProperties>
            <xades:SigningTime>2026-09-30T17:40:22Z</xades:SigningTime>
            <xades:SigningCertificateV2> ... </xades:SigningCertificateV2>
          </xades:SignedSignatureProperties>
          <xades:SignedDataObjectProperties>
            <xades:DataObjectFormat ObjectReference="#r-97744c13a070b011-1">
              <xades:MimeType>text/xml</xades:MimeType>
            </xades:DataObjectFormat>
          </xades:SignedDataObjectProperties>
        </xades:SignedProperties>
      </xades:QualifyingProperties>
    </Object>
  </Signature>
</Invoice>

16.8 Good to know

SituationWhat happens
No valid serial number in new XadesSignature("...")The library works in demonstration mode: it writes a message and waits 10 seconds before each signature and verification.
HashAlgorithm.SHA1A NotSupportedException is thrown: SHA1 is not used for new XAdES signatures. Old SHA-1 signatures can still be verified.
XAdES-T, -LT or -LTA without TimeStamping.ServerUrlAn ArgumentException is thrown: the time stamp server is required.
DigitalSignatureCertificate not setA NullReferenceException is thrown.
The signing failsThe output file is deleted (unless it is the input file), so you never keep a half-made signed document.
A detached signature where the output is the signed fileAn ArgumentException is thrown: the signature file must be another file.
Older signatures (XMLDSig)

The library has also a class for the older XMLDSig signatures. For new documents use XadesSignature: XAdES contains XMLDSig and adds the signing time, the signer's certificate, time stamps and long-term validation data.

17. Problems and solutions

What you seeWhat to do
Windows protected your PC when you start the setupWindows SmartScreen does not know the new setup file yet. Click More info and then Run anyway, if you downloaded the file from www.signfiles.com (section 2).
Invalid license code.The serial number has 20 characters. Retype it exactly as you received it, without extra characters (section 3).
Digital certificate is not set. In order to add a signature on your documents, select a digital certificate.Click Select the Digital Certificate... and choose a certificate (section 6).
The certificate of the smart card or USB token is not in the listConnect the token and check that its middleware is installed. The certificate must be in the Windows Certificate Store: open certmgr.msc and look in Personal. If it is not there, use the options of the middleware that copy or register the certificates in the Windows store (section 6.2). Then open the certificate window again.
The digital certificate ... expired on ... An expired certificate cannot be used to sign documents.Choose a valid certificate or renew yours with your provider.
The private key of the digital certificate cannot be found.The certificate on the computer has no key to sign with. Import the full certificate (including the private key), or connect your USB token.
PFX digital signature certificate error ...The PFX password is wrong, or the file is damaged. Retype the password in the certificate window.
The smart card or token PIN is rejectedCorrect the PIN in the certificate window. The program will not keep trying with a wrong PIN, to protect the token.
The XAdES-T signatures require a time stamp server, but the Time Stamp Server URL is not valid.Open Time Stamp Settings... and type a valid address (section 8). Also check your Internet connection.
The selected folder does not contain XML documents.Pick a folder that contains .xml files.
The destination file for the signed document already exists. Would you like to overwrite the existing file?Click Yes to replace it, or No and choose another file name.
XML Signer has expired. Would you like to purchase the registered version...?The trial period ended. Register with your license code (section 3).
The batch command does nothing, or the result code is 2Read the message in the command window and the file errorlog.txt (section 12). The usual causes: a path that ends with a backslash inside quotes, a configuration file that does not exist, an expired certificate, or a program that is not registered.
Viewer: The document does not contain XML digital signatures.The file was never signed (or is not the signed copy). Open the signed file instead.
Viewer: The XML signature is not validThe document was changed after signing, or the signature is damaged. Get the original signed file again.
Library: the program waits 10 seconds and writes This is a demonstration of the digital signature softwareThe serial number of the library is missing or not valid. Write the serial number in new XadesSignature("...") (section 16).
Library: NotSupportedException when you signThe hash algorithm is SHA1, which is not used for new XAdES signatures. Use SHA256, SHA384 or SHA512.
Need more help?

Visit www.signfiles.com or use the contact link shown in the registration window, www.signfiles.com/contact.

18. Glossary

TermIn plain words
Digital signatureAn electronic seal added to a document. It shows who signed and that the content was not changed.
Digital certificateYour electronic identity card, issued by a certification authority. It contains your name and a key used to sign.
PFX fileA file (.pfx or .p12, the PKCS#12 format) that holds a certificate and its private key, protected by a password.
Windows Certificate Store (Microsoft Store)The place where Windows keeps the certificates installed on the computer or available from tokens and smart cards. It is not the Microsoft Store of applications. Open it with certmgr.msc.
Private keyThe secret part of your certificate. Only you should have it. It is what makes a signature yours.
Smart card / USB tokenA small device that keeps your private key and signs inside it, so the key cannot be copied. It is protected by a PIN.
MiddlewareThe software delivered with a smart card or token (for example SafeNet Authentication Client). It lets Windows and the programs use the device, and usually adds its certificates to the Windows store.
HSMHardware Security Module: a device that keeps the keys of a company and signs on request.
CSP / KSPCryptographic Service Provider / Key Storage Provider: the component that manages the private key. Certificate Service Provider in XML Signer shows its name.
Windows SmartScreenA protection of Windows that warns you about programs it does not know yet. A warning does not mean that the program is infected.
Hash (SHA256)A short fingerprint of the document. If the document changes, the fingerprint changes.
XMLDSigThe general standard for XML signatures.
XAdESThe European standard that extends XMLDSig with signing time, signer information, time stamps and long-term validation data.
Enveloped / detached signatureAn enveloped signature is written inside the XML document. A detached signature is a separate file that refers to the signed file.
Time stamp / TSAA proof of time issued by a trusted independent service (Time Stamp Authority).
OCSP / CRLWays to ask the certification authority whether a certificate was cancelled (revoked). The answers can be stored in the signature.
Self-signed certificateA certificate you create yourself. It works technically but nobody else trusts it. Use it only for tests.
CanonicalizationNormalizing the XML text (spaces, attribute order...) before signing so that harmless formatting differences do not break the signature.
Serial number (license code)The code that registers XML Signer, received after the purchase. The Signature Library has its own serial number.
SignLib (Signature Library)The .NET library on which XML Signer is built. It lets programs and PowerShell scripts create and verify the same signatures.
Batch signingSigning many documents in one operation, or automatically, without a user, from the command line.

Every effort has been made to make this manual as complete and accurate as possible, but no warranty or fitness is implied. The information provided is on an “as is” basis. The author shall have neither liability nor responsibility to any person or entity with respect to any loss or damages arising from the information contained in this manual.

.NET, Windows, PowerShell, SmartScreen and Visual Studio are trademarks of Microsoft Corporation. All other trademarks are the property of their respective owners.