XML Signer User Manual
Add a digital signature to your XML documents in a few clicks, sign whole folders automatically, and check signed documents with XML Signer Viewer. No technical knowledge needed; developers find PowerShell, C# and VB.NET examples at the end.
1. What is XML Signer?
An XML document (for example an electronic invoice) can be changed by anyone who has the file. A digital signature solves two problems:
- Who signed it? The signature is created with your personal digital certificate, so it proves your identity.
- Was it changed? If even one character of the document is modified after signing, the signature is reported as not valid.
The main function of XML Signer is to sign XML files with X.509 digital certificates. You can sign a single document, or select an input folder and an output folder and sign hundreds of documents at once (bulk signing), which is ideal for the documents of a company. The same signatures can be created automatically, without any window, from the command line (section 12).
The product has two programs:
| Program | What it does |
|---|---|
| XML Signer | Adds digital signatures to one XML document or to a whole folder of documents. Works from the window or from the command line. |
| XML Signer Viewer | Opens a signed XML document and tells you who signed it, when, and whether the signature is still valid. |
The signature is added inside the XML file. The original content stays exactly as it was. The signed copy is saved in the destination you choose, so your original file is never lost.
Who is this manual for?
- Users — sections 1 to 13 explain, step by step, how to install the product, register it, choose a certificate and sign documents.
- Developers and administrators — sections 14 to 16 explain that XML Signer is built on the Signature Library (SignLib), and show how to create the same XAdES signatures from Windows PowerShell, C# or VB.NET. One of the purposes of XML Signer is to let you see what the library can do before you write a single line of code.
Useful links
| What | Address |
|---|---|
| XML Signer product page (information, purchase, download) | https://www.signfiles.com/xml-signer/ |
| Download XML Signer (free trial) | https://www.signfiles.com/apps/XMLSigner.msi |
| Signature Library (SignLib) used by XML Signer | https://www.signfiles.com/signature-library/ |
| Signature Library code samples | https://www.signfiles.com/code-samples/ |
| Support and contact | https://www.signfiles.com/contact/ |
2. Product installation
We recommend installing the product with an Administrator account. After the setup file is verified, the operating system might ask for your permission to install the program: click Yes.
What you need
- Windows 7 or later (including Windows 10, Windows 11 and Windows Server).
- Microsoft .NET Framework 4.6.2 or newer. It is already part of Windows 10 and Windows 11.
- A digital certificate to sign with. If you do not have one yet, you can create a test certificate (section 9).
Installation steps
- Download the setup file. Get
XMLSigner.msifrom the product page and run it. - If Windows SmartScreen appears, allow the program to run. You may see the window Windows protected your PC. Click More info and then Run anyway. See the explanation below.
- Read the license agreement. Read the EULA (End-User License Agreement). If you want to continue, select I Agree and click Next until the setup is finished.
- Start the program. The setup installs XML Signer and XML Signer Viewer. Start them from the Windows Start menu. By default the files are in the
Secure Soft\XML Signerfolder ofProgram Files(on a 64-bit Windows:C:\Program Files (x86)\Secure Soft\XML Signer).

What is Windows SmartScreen?
SmartScreen is a protection built into Windows. When you run a program you downloaded, Windows compares it with a list of programs that are known and were already downloaded by many people. A program that Windows does not know yet, for example a new version that was published recently, is shown as an unrecognized app, and the window below appears.

This message does not mean that the file contains a virus. It only means that Windows has no reputation data about it yet. To continue:
- Click More info. The name of the file and of the publisher are displayed.
- Click Run anyway and the setup starts.
Run the setup only if you downloaded it from www.signfiles.com. If you prefer, you can also right-click the downloaded XMLSigner.msi, choose Properties, tick Unblock (at the bottom of the General tab) and click OK. The setup then starts without the SmartScreen message.
3. Trial period and product registration
A new, unregistered installation works for a trial period of about 30 days. The title of the window shows how much is left, for example XML Signer - Expires in 30 days, and the buttons Register Now and Buy Now! are visible.

How to register the product
- Get a serial number. To register the product you need a serial number (also called license code). You can buy it online directly from the product page, https://www.signfiles.com/xml-signer/. You can also click Buy Now! in the program, which opens the same page.
- Open the registration window. Open XML Signer and click the Register Now button (or Help → Register Now...).
- Type the license code. Enter the received serial in the first box. The second box, Licensed to (optional), is for a name: if you type one, it is shown in the title of the window.
- Click Register. If the serial number is correct, the product is successfully registered.



- The license code has 20 characters (letters and digits). Type it exactly as you received it. The messages License code cannot be empty. and Invalid license code. mean that the box is empty, or that the code was mistyped.
- The registration is saved for the Windows user account that registered the program. If another person uses the same computer with a different account, the registration is done once more with the same code.
- XML Signer Viewer is installed together with XML Signer and has no registration window.
When the trial has expired, the title shows Expired on and a date, and XML Signer no longer signs documents until you register.
4. Sign your first document
This is the whole process. It takes less than a minute once you have a certificate.

- Choose the document. Keep A single XML document selected. Click the ... button under Source and select the XML file you want to sign.
- Choose where to save the signed copy. Click the ... button under Destination and pick a folder and a file name (for example
invoice-001-signed.xml). The destination must be a different file from the source. - Select your digital certificate. Click Select the Digital Certificate.... Choose the certificate from the Windows store, or a
.pfxfile, and click OK (details in section 6). - Leave the format on the recommended value. XAdES-B-B - basic (recommended) and SHA256 are already selected and are the right choice for most uses (see section 7).
- Click Apply Digital Signature. After a moment you see the message The file was digitally signed succesfully. Your signed document is in the destination you chose.


Drag a file onto the program icon, or right-click an XML file and choose Open with → XML Signer. The file is selected as the source automatically.
5. The main window
| Item | What it does |
|---|---|
| Digitally sign | Choose A single XML document or A folder with XML documents (all .xml files of the folder are signed). |
| Source | The document (or folder) you want to sign. Use the ... button to browse. |
| Destination | Where the signed document (or the signed documents) will be saved. |
| Signature Format | The kind of signature to create. The default, XAdES-B-B - basic, is the right choice for normal use. See section 7. |
| Hash Algorithm | The mathematical fingerprint used to detect changes: SHA256 (default), SHA384 or SHA512. Keep SHA256 unless the party receiving your documents asks for another one. The older SHA1 is not supported. |
| Canonicalization | Only used for the XMLDSig format (the box is grayed out for XAdES). It tells the program how to normalize the XML before signing. Keep Default unless you were told to use another value. |
| Select the Digital Certificate... | Opens the certificate window (section 6). Below this button you always see which certificate is currently selected and until when it is valid. |
| Time Stamp Settings... | Available only for the formats that use a time stamp (XAdES-B-T, -LT and -LTA). See section 8. |
| Apply Digital Signature | Signs the document or the folder. While a folder is being signed you can stop it with the Cancel button in the bottom bar; the bar also shows the progress. |
Menus
| Menu | Commands |
|---|---|
| File | Open (choose a document or folder), Apply Digital Signature..., Save Configuration, Save Configuration As..., Load Configuration..., Exit. |
| Tools | Select the Digital Certificate..., Time Stamp Settings..., Create a self-signed Digital Certificate..., Restore Defaults (asks you to confirm, then sets all options back to their original values). |
| Help | About... (program version and registration status) and Register Now... (only while the program is not registered). |
6. Digital certificates
A digital certificate is your electronic identity card, issued by a certification authority. To sign with XML Signer you need one. This section explains where certificates are kept and how to select the one you want to sign with.
6.1 Where the certificates are stored
A certificate that can sign documents has two parts: a public key (the part other people see, inside the certificate) and a private key (the secret part, which only you have). The digital signature is created with the private key. The certificates are kept in two places:
- in the Windows Certificate Store (called Microsoft Store in the program);
- in a PFX (or P12) file.
The Windows Certificate Store (Microsoft Store)
The Windows Certificate Store is the place where Windows keeps the certificates of the computer and of each user. In XML Signer it appears as Windows Certificate Store and Certificates Available on Microsoft Store.
The certificate store has nothing to do with the Microsoft Store where you download applications. It is only the traditional name of the list of certificates of Windows.
To see the certificates of your account:
- Press Win + R, type
certmgr.mscand press Enter. - Open Personal → Certificates.
(The older way still works: Internet Options → Content tab → Certificates button, tab Personal.)
To create digital signatures, the certificates of the Personal store are used. They must have a public and a private key. You can check this by opening a certificate: in the General tab Windows writes You have a private key that corresponds to this certificate.

The private key itself can be stored:
- on the file system of the computer (for example, an imported PFX file);
- on a cryptographic smart card or USB token (like Aladdin eToken or SafeNet iKey) — see 6.2;
- on an HSM (Hardware Security Module), a device that keeps keys for a company.
The certificates you can use are listed per store location: Current User (your own certificates, the usual case) or Local Machine (certificates installed for all the users of the computer).
PFX and P12 files
Another way to keep a digital certificate is a PFX (or P12) file. The file contains the public and the private key of the certificate, and it is protected by a password, to keep the key pair safe.
A PFX/P12 file can be imported into the Windows Certificate Store: just open the file (double-click it) and follow the Certificate Import Wizard. After that, the certificate is available in the Personal list and you can select it from the Windows store without the file.
6.2 Certificates stored on smart cards or USB tokens
If your certificate is stored on a smart card or on a USB token (like Aladdin eToken or SafeNet), the private key never leaves the device: it signs inside the device. For XML Signer to use it, the certificate must appear in the Windows Certificate Store (6.1).
Usually, the driver of the smart card or its middleware (the software delivered with the token) installs the certificate in the Windows store automatically when the token is connected. If the certificate does not appear in the list, ask your vendor how to add it to the store, and look at the options of the middleware, like below:


Once the certificate is in the store, select it in XML Signer as described in 6.3.

Normally Windows asks for the PIN of the card every time you sign. If you do not want the PIN window (for example for batch signatures, section 12), tick Smart Card PIN and type the PIN. The PIN is saved encrypted in the configuration, it belongs to the selected certificate, and it is cleared when you select another certificate. If the card rejects the PIN, XML Signer stops using it (so your card does not get locked by repeated wrong attempts): correct it in this window and try again.
6.3 Select the digital certificate for creating signatures
To digitally sign a document, a digital certificate must be selected first. Click Select the Digital Certificate... (or Tools → Select the Digital Certificate...). The certificate can be stored in the Windows store or in a PFX file.

Option A: a PFX file
Some certificates are delivered as a file with the extension .pfx (or .p12), protected by a password.
- Select PFX digital certificate file.
- Click ... and pick your
.pfxfile (or type its path). - Type the PFX file password. The Show button next to it displays the details of the certificate so you can check you picked the right one.
- Click OK.
Option B: a certificate installed in Windows
Certificates installed on the computer, or stored on a USB token or smart card, appear in the Windows Certificate Store.

- Select Windows Certificate Store.
- In Certificate Store choose Current User (your own certificates, the usual case) or Local Machine (certificates installed for the whole computer).
- Pick your certificate from the list Certificates Available on Microsoft Store. The list shows the name of the owner, the issuer and the expiry date; an expired certificate is marked EXPIRED and is placed at the end. Show displays the full certificate.
- Click OK.
Certificate Information
At the bottom of the window, Certificate Information summarizes the selected certificate: to whom and by whom it was issued, until when it is valid, and Certificate Service Provider. The last one is the name of the software (or of the device driver) that manages the private key of the certificate. It helps you understand where the key is:
| Provider shown | Where the private key is |
|---|---|
| Microsoft Software Key Storage Provider, Microsoft Enhanced Cryptographic Provider | In your Windows account, on the computer (for example an imported PFX file). |
| eToken Base Cryptographic Provider, SafeNet Smart Card Key Storage Provider or similar names from the token vendor | On a smart card or USB token. A PIN is needed to sign. |
(The abbreviations are CSP, Cryptographic Service Provider, for the classic providers, and KSP, Key Storage Provider, for the newer ones. You do not have to choose them: XML Signer uses the provider of the certificate.) If the private key is not available on this computer, the line The private key is not available is added.
Long-term validation data
At the bottom of the window, Revocation data of the XAdES-LT and XAdES-LTA signatures chooses what proof of validity is saved inside those signatures (see section 7):
- OCSP responses (CRL only when OCSP is not available) — the default and the best choice for most users.
- CRLs, CRLs and OCSP responses, or No revocation data (only the certificates).
- Maximum size of a CRL (default 1024 kilobytes) limits how large a revocation list may be to be included.
The button Create a self-signed Certificate... at the bottom left is explained in section 9.
If the certificate is expired or not valid yet, or its private key is missing, XML Signer refuses to sign and explains why. Renew the certificate or choose another one.
7. Signature formats
The format decides how much information is stored inside the signature. If you are not sure, keep the first one.
| Format in the list | What it adds | When to use it |
|---|---|---|
| XAdES-B-B — basic recommended | The signature and the signer's certificate. | Everyday use: invoices, contracts, exchanged documents. Works offline and needs no extra settings. |
| XAdES-B-T — with time-stamp | A trusted time stamp from an independent server that proves the exact time of signing. | When you must prove when the document was signed. Needs an Internet connection (see section 8). |
| XAdES-B-LT — long term validation | Time stamp plus the certificates and revocation proofs (OCSP/CRL) of the signer. | Documents that must stay verifiable for years, even after the certificate expires or the issuer's servers are gone. |
| XAdES-B-LTA — long term archival | Everything from LT plus an archive time stamp. | Archives that must remain provable for many years. |
| XMLDSig — old standard | A basic signature in the older, general format. | Only when the receiving system specifically asks for plain XMLDSig. It has the extra Canonicalization option. |

XAdES is the European standard for advanced electronic signatures. The letters B, T, LT and LTA come from the standard: Basic, Time-stamp, Long Term and Long Term Archival.
8. Time stamp settings
A time stamp is issued by a Time Stamp Authority (TSA), an independent service. It proves that your signature existed at a given moment and cannot be back-dated. It is used by XAdES-B-T, -LT and -LTA. Open it with Time Stamp Settings....

| Setting | Meaning |
|---|---|
| Time Stamp Server URL | The web address of the TSA service. The program starts with https://ca.signfiles.com/TSAServer.aspx. Use the address given by your provider if you have your own. |
| Time Stamp Server requires authentication | Tick it and type the Username and Password if your provider requires them. |
| Time Stamp Server Policy | Tick it only if your provider asked you to send a policy identifier, and type it. |
| Use NONCE | A random number that protects the request from being replayed. Leave it ticked. |
| Hash algorithm used for request | SHA256 by default. |
| Restore Defaults | Puts all these values back to the original ones. |
The computer must be able to reach the time stamp server while signing. If the address is not valid, XML Signer tells you to set it here before signing.
9. Creating a test certificate
If you do not have a certificate yet and only want to try the program, XML Signer can create a self-signed one. Open Tools → Create a self-signed Digital Certificate... (or the button in the certificate window).

- Choose where to save it: On Microsoft Certificate Store or On a password protected PKCS#12 PFX file (you will be asked for the file name and a password).
- Type Issued to (your name, required) and, if you wish, the organization, unit, title, e-mail address and country code.
- Choose the Validity period (default 3 years), the RSA Key Algorithm length (default 2048 bits) and the Signature Algorithm (default SHA256WithRSA). The defaults are fine.
- Keep Set as current digital certificate ticked to use it right away, then click OK.
Nobody except you trusts a self-signed certificate. Other people's programs will show that the signer is unknown. For real documents, use a certificate issued by a recognised certification authority.
10. Signing a whole folder
To sign many documents at once, select A folder with XML documents.

- Under Source choose the folder with your XML documents.
- Under Destination choose another folder. Each
.xmlfile of the source folder is signed and saved with the same name in the destination folder. The source and the destination must be different folders. - Click Apply Digital Signature. When it finishes you see how many documents were signed.

If files with the same names already exist in the destination, the program asks you first: Would you like to overwrite the existing file? (or, for a folder, how many documents will be overwritten). If a folder contains no XML documents you are told: The selected folder does not contain XML documents.
11. Saving your settings
The program remembers your choices (certificate, format, hash algorithm, time stamp server...) the next time you start it. You can also keep several sets of settings in files — for example one for invoices and one for contracts:
- File → Save Configuration As... saves the current settings in a file you name.
- File → Load Configuration... loads them again.
- Tools → Restore Defaults returns everything to the original values.
A saved configuration file is also what the command line uses to sign documents automatically.
12. Batch signatures (automatically made without user intervention)
XML Signer can also sign without showing its window, for example from a scheduled task, from a script or from another program. Nobody has to click anything: the program reads the settings from a configuration file, signs, and closes.
By default, XML Signer is installed in the folder C:\Program Files (x86)\Secure Soft\XML Signer (on a 32-bit Windows: C:\Program Files\Secure Soft\XML Signer) and the program is XML Signer.exe.
Command line parameters
"XML Signer.exe" <source file> <destination file | destination folder> [<configuration file>]
"XML Signer.exe" <source folder> <destination folder> [<configuration file>]
"XML Signer.exe" <XML file | folder> (opens the window with the file or folder selected)
"XML Signer.exe" /? (shows this help)
- source folder: all the
*.xmlfiles of the folder are signed, with the same names, in the destination folder. - configuration file: a file saved with File → Save Configuration As.... When it is not given, the current configuration of the window is used.
- Do not end a path written between quotes with a backslash: write
"C:\Folder", not"C:\Folder\". Windows would read the last backslash and quote as one character and the arguments would be mixed up.
Sign one file
To automatically sign a file, use a command like this one:
c:\Program Files (x86)\Secure Soft\XML Signer>"XML Signer.exe" c:\TestFile.xml "c:\TestFile[signed].xml"
Sign a folder
To automatically sign all the files of a folder:
c:\Program Files (x86)\Secure Soft\XML Signer>"XML Signer.exe" c:\InputFolder c:\OutputFolder
Custom configuration
In some cases you need a different signature configuration (for example a different certificate or signature format) for different files or folders. To save a specific configuration, open the window, set everything you want, and go to File → Save Configuration As... Save the configuration in a file. Later you can use that file in batch mode to apply a different signature configuration on the signed files.
To automatically sign a folder using a custom configuration:
"XML Signer.exe" c:\InputFolder c:\OutputFolder c:\config-client2.xml
Because nobody is there to answer, choose a certificate that does not need any interaction: a PFX file (its password is saved in the configuration, encrypted) or a smart card certificate with the Smart Card PIN saved (section 6.2). The smart card must be connected. The certificate must be valid: an expired certificate stops the signing, with the result code 2.
Result codes
| Code | Meaning |
|---|---|
| 0 | Success. |
| 1 | The signing failed (for a folder: at least one file failed). |
| 2 | The signing could not start: invalid arguments or configuration, the certificate is not valid, or XML Signer is not registered. |
XML Signer is a Windows application, so the command prompt does not wait for it. To wait and read the result code:
cmd: start "" /wait "XML Signer.exe" C:\Demo\Invoices C:\Demo\Signed C:\Demo\invoices.config
echo %errorlevel%
PowerShell: (Start-Process "XML Signer.exe" -ArgumentList '"C:\Demo\Invoices" "C:\Demo\Signed" "C:\Demo\invoices.config"' -Wait -PassThru).ExitCode
Log files
Every file signed from the command line is recorded in log.txt, and every error in errorlog.txt. Both are in your user profile, in the folder %APPDATA%\Secure Soft\XML Signer\<version> (the last part is a folder named after the version of the program). The error messages are also written in the command window.
Set up everything once in the window, use Save Configuration As..., and then create a task in the Windows Task Scheduler that starts XML Signer.exe with the source folder, the destination folder and the configuration file. Use the same Windows account for the task that you used to set up the certificate and the registration.
13. XML Signer Viewer
XML Signer Viewer is the second program of the product. Use it to check a signed document you created or received.
Opening a document
Start XML Signer Viewer, click ... next to Source XML file and pick the signed file. You can also right-click a file and choose Open with → XML Signer Viewer.

What you see
| Line | Meaning |
|---|---|
| Signers list | Every person who signed the document, numbered. Choose one to see the details below. A document can be signed by several people. |
| Issuer name | The certification authority that issued the signer's certificate. |
| Subject name | The owner of the certificate, that is, the signer. |
| Signature format | For example XAdES-B-B (see section 7). |
| Signing date | When the document was signed. The note (declared by the signer) means it comes from the signer's own computer clock. A trusted time appears only when the signature has a time stamp. |
| Signature algorithm | The technique used, for example RSA-SHA256. |
| Certificate status | Certificate is valid, or Certificate is not valid with the reason (for example expired). |
| Signature integrity | The most important line. The XML signature is valid means the document is exactly as it was when signed. The XML signature is not valid means it was changed or the signature is damaged. |
| Signature time stamp, Archive time stamps, Validation data | Shown for the T, LT and LTA formats: who issued the time stamp and whether it matches the signature, and how many certificates and OCSP/CRL proofs are stored inside. |
A document that was changed
If somebody changes the document after it was signed (here, the amount in an invoice), the Viewer says so clearly:

Ask the sender for the original signed file.
Buttons
- Show certificate — opens the Windows certificate window for the selected signer, with all its details.
- Open unsigned XML file — opens a copy of the document without the signatures in the program associated with XML files on your computer.
- Save unsigned XML file — saves a copy of the document without the signatures.
- About... and Quit.

The Viewer checks that the document was not changed and that the certificate is valid. Whether you trust the signer is your decision: check the Issuer name and the Subject name. A self-signed test certificate shows the same name for both.
14. The Signature Library behind XML Signer
XML Signer is an application built on the Signature Library (SignLib), a library for .NET that creates and verifies digital signatures: PDF (PAdES), CAdES / PKCS#7, XML (XAdES), Office and more. Everything XML Signer does is available to your own programs and scripts through the library:
- Library page: https://www.signfiles.com/signature-library/
- Download (library, samples and PowerShell scripts): https://www.signfiles.com/sdk/SignatureLibrary.zip
- Code samples: https://www.signfiles.com/code-samples/
The library works with Windows PowerShell, C#, VB.NET and ASP.NET, on .NET Framework and on the recent .NET versions, and it supports certificates from PFX files, from the Windows store and from smart cards, USB tokens and HSMs.
XML Signer is also a demonstration of the library. Before you write any code, use the window to try a signature format, a hash algorithm, a time stamp server or a certificate, and save the result of your test. Every choice you make in the window is one property of the library (see the table below), and the signed file you get is exactly what your code will produce. The XML Signer Viewer shows you how a signature created by your code looks to the people who receive it.
From the window to the code
XAdES signatures are created with the class SignLib.Xml.XadesSignature. The table shows what each setting of XML Signer is in the library.
| In XML Signer | In the library |
|---|---|
| Signature Format: XAdES-B-B, -B-T, -B-LT, -B-LTA (section 7) | signature.SignatureStandard = XadesSignatureStandard.XadesB (or XadesT, XadesLT, XadesLTA) |
| Hash Algorithm | signature.HashAlgorithm = HashAlgorithm.SHA256 (or SHA384, SHA512) |
| Digital certificate from a PFX file | DigitalCertificate.LoadCertificate(pfxFile, password) |
| Digital certificate from the Windows store or a smart card | DigitalCertificate.LoadCertificate(...) with a search criterion, or without parameters to show the selection window |
| Smart Card PIN | DigitalCertificate.SmartCardPin = "..." |
| Time Stamp Server URL, user name, password, policy, NONCE, hash (section 8) | signature.TimeStamping.ServerUrl, .UserName, .Password, .PolicyOid, .UseNonce, .HashAlgorithm |
| Revocation data of the LT and LTA signatures | signature.LtvLevel = XadesLtvLevel.IncludeOcspOnly (or IncludeCrl, IncludeCrlAndOcsp, None) |
| Maximum size of a CRL (in kilobytes in the window) | signature.MaxCrlSize (in bytes in the code) |
| Apply Digital Signature | signature.ApplyDigitalSignature(inputFile, outputFile) |
| Create a self-signed certificate (section 9) | the class X509CertificateGenerator |
| XML Signer Viewer (section 13) | GetNumberOfSignatures, VerifyDigitalSignature, GetDigitalSignatureCertificate, GetSignatureAlgorithm |
The library can do more than the window: detached signatures for files of any type, several signers, the place and the commitment of the signature, an explicit signature policy and the renewal of archive time stamps. They are shown in section 16.
15. Digitally sign XML files using Windows PowerShell
The main functions of XML Signer are available in the SignLib library, which you can download from this link: https://www.signfiles.com/sdk/SignatureLibrary.zip
To digitally sign an XML file using Windows PowerShell, simply download the library above and inspect the Signature Library\PowerShell Scripts folder. There you find ready-made scripts for the other kinds of documents; the script below does the same for XML, using the XAdES signature of XML Signer.
The script
Save it as signXmlDocument.ps1, in the same folder with SignLib.dll. It creates a test PFX certificate on the fly, signs the file in the XAdES-B-B format (SHA256) and verifies the result.
#digitally sign an XML file in the XAdES format, using a PFX certificate created on the fly
#the script can be configured to use an existing PFX file or a certificate loaded from Microsoft Store (smart card certificate)
if ($args.Length -eq 0)
{
echo "Usage: signXmlDocument.ps1 <unsigned file> <signed file>"
}
else
{
#SignLib.dll must be on the same folder as the script (or write its full path)
$DllPath = Join-Path $PSScriptRoot 'SignLib.dll'
[System.Reflection.Assembly]::LoadFrom($DllPath) | Out-Null
#create a PFX digital certificate
$generator = new-object -typeName SignLib.Certificates.X509CertificateGenerator("serial number")
$pFXFilePassword = "tempP@ssword"
$generator.Subject = "CN=Your Certificate, E=useremail@email.com, O=Organization"
$generator.Extensions.AddKeyUsage([SignLib.Certificates.CertificateKeyUsage]::DigitalSignature)
$generator.Extensions.AddEnhancedKeyUsage([SignLib.Certificates.CertificateEnhancedKeyUsage]::DocumentSigning)
echo "Create the certificate..."
$certificate = $generator.GenerateCertificate($pFXFilePassword)
#digitally sign the file in XAdES format (XAdES-B-B, SHA256)
$sign = new-object -typeName SignLib.Xml.XadesSignature("serial number")
$sign.DigitalSignatureCertificate = [SignLib.Certificates.DigitalCertificate]::LoadCertificate($certificate, $pFXFilePassword)
echo "Perform the digital signature..."
$sign.ApplyDigitalSignature($args[0], $args[1])
#verify the signature
echo ("Signatures: " + $sign.GetNumberOfSignatures($args[1]))
echo ("Valid: " + $sign.VerifyDigitalSignature($args[1]))
}
How to run it
How to run the Windows PowerShell script from the command line:
powershell -executionPolicy bypass -file d:\signXmlDocument.ps1 d:\test.xml "d:\test[signed].xml"
The result in the window:
Create the certificate...
Perform the digital signature...
Signatures: 1
Valid: True
- Replace
"serial number"with the serial number you received for the library. Without it the library works in demonstration mode: it writes This is a demonstration of the digital signature software and waits 10 seconds before every operation. -executionPolicy bypassallows this one script to run without changing the security settings of the computer.- To sign with an existing PFX file, remove the certificate generator and use
[SignLib.Certificates.DigitalCertificate]::LoadCertificate("d:\certificate.pfx", "password"). For a smart card certificate from the Windows store use the methods described in section 16.
16. Digitally sign XML files using C# or VB.NET
The main functions of XML Signer are available in the SignLib library (download). To digitally sign a file using C# or VB.NET, download the library, add a reference to SignLib.dll in your project, and inspect the sample projects of the package and the code samples page.
XML documents are signed with the class XadesSignature (namespace SignLib.Xml). It creates XAdES signatures, the European standard for advanced electronic signatures, at the four baseline levels B-B, B-T, B-LT and B-LTA (section 7), and verifies them.
All the examples below use these namespaces. Every example was run with the library to check the result.
using SignLib; // HashAlgorithm
using SignLib.Certificates; // DigitalCertificate
using SignLib.Timestamping; // time stamp settings
using SignLib.Xml; // XadesSignature and its options
16.1 Sign an XML document and verify the signature
The smallest program: load a certificate from a PFX file, sign, and verify. The signature format is XAdES-B-B and the hash is SHA256, exactly like the defaults of XML Signer.
using SignLib;
using SignLib.Certificates;
using SignLib.Xml;
// "serial number" is the serial number of the library
XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");
// apply the digital signature: the input file is not changed, the signed copy is saved in the output file
signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");
// verify the signature
XadesSignature verifier = new XadesSignature("serial number");
Console.WriteLine("Signatures: " + verifier.GetNumberOfSignatures("invoice-signed.xml"));
Console.WriteLine("Valid: " + verifier.VerifyDigitalSignature("invoice-signed.xml"));
Console.WriteLine("Signer: " + verifier.GetDigitalSignatureCertificate("invoice-signed.xml").Subject);
Console.WriteLine("Algorithm: " + verifier.GetSignatureAlgorithm("invoice-signed.xml"));
The result:
Signatures: 1
Valid: True
Signer: CN=Elaine Smith, O=Demo Company, C=US
Algorithm: RSA-SHA256
The same example in VB.NET:
Imports SignLib
Imports SignLib.Certificates
Imports SignLib.Xml
Module Module1
Sub Main()
Dim signature As New XadesSignature("serial number")
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate("d:\certificate.pfx", "123456")
signature.SignatureStandard = XadesSignatureStandard.XadesB
signature.HashAlgorithm = HashAlgorithm.SHA256
'apply the digital signature
signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml")
Dim verifier As New XadesSignature("serial number")
Console.WriteLine("Signatures: " & verifier.GetNumberOfSignatures("invoice-signed.xml"))
Console.WriteLine("Valid: " & verifier.VerifyDigitalSignature("invoice-signed.xml"))
End Sub
End Module
16.2 Signature levels, time stamp and long-term validation
The level of the signature is chosen with SignatureStandard. The levels that contain a time stamp (XadesT, XadesLT, XadesLTA) need the address of a time stamp server (section 8).
XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");
signature.HashAlgorithm = HashAlgorithm.SHA384; // SHA256 (default), SHA384 or SHA512
signature.SignatureStandard = XadesSignatureStandard.XadesLT; // XadesB, XadesT, XadesLT or XadesLTA
signature.TimeStamping.ServerUrl = new Uri("https://ca.signfiles.com/TSAServer.aspx");
signature.LtvLevel = XadesLtvLevel.IncludeOcspOnly; // the revocation data saved in the LT and LTA signatures
signature.ApplyDigitalSignature("invoice.xml", "invoice-lt.xml");
If the time stamp server asks for authentication, or you want to set other options of the request, use the other properties of TimeStamping:
signature.TimeStamping.UserName = "user"; // only if the server requires authentication
signature.TimeStamping.Password = "password";
signature.TimeStamping.UseNonce = true; // a random number that protects the request
signature.TimeStamping.HashAlgorithm = HashAlgorithm.SHA256;
signature.MaxCrlSize = 2 * 1024 * 1024; // the largest CRL that is included, in bytes (default: 1 MB)
Renewing the archive time stamp (XAdES-B-LTA)
A XAdES-B-LTA signature is made to be kept for many years. After some time, add a new archive time stamp, before the certificate of the time stamp server expires. The signing certificate is not needed for this.
XadesSignature archive = new XadesSignature("serial number");
archive.TimeStamping.ServerUrl = new Uri("https://ca.signfiles.com/TSAServer.aspx");
archive.AddArchiveTimestamp("invoice-lta.xml", "invoice-lta-renewed.xml");
16.3 A certificate from the Windows store or a smart card
When the certificate is in the Windows store (for instance, a smart card certificate, section 6.2), load it with a search criterion. No window is shown, so the code can run without a user.
XadesSignature signature = new XadesSignature("serial number");
// the first certificate of the current user whose common name (CN) is "Elaine Smith"
// true = only the valid certificates (issued by a trusted authority); false = any certificate, also a self-signed test one
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(true, DigitalCertificateSearchCriteria.CommonNameCN, "Elaine Smith");
// the PIN of the smart card, to avoid the PIN window. It applies to the next signature, made on this thread
DigitalCertificate.SmartCardPin = "1234";
signature.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");
Other search criteria are the other fields of the subject (OrganizationO, EmailE...), the thumbprint and the serial number of the certificate. To let the user choose the certificate in a Windows window, call DigitalCertificate.LoadCertificate() without parameters.
16.4 Detached signatures: sign a file of any type
By default the signature is added inside the XML document (enveloped). With a detached signature the signature is a separate XML file that refers to the signed file. The signed file can be of any type (PDF, DOCX, ZIP...) and it is not changed. The original file is needed to verify the signature.
XadesSignature signature = new XadesSignature("serial number");
signature.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\certificate.pfx", "123456");
signature.SignaturePackaging = XadesSignaturePackaging.Detached;
signature.ApplyDigitalSignature("contract.pdf", "contract.pdf.xml");
// verify: the signature file and the signed file
XadesSignature verifier = new XadesSignature("serial number");
bool valid = verifier.VerifyDigitalSignature("contract.pdf.xml", "contract.pdf"); // False if contract.pdf was changed
16.5 Several signatures in the same document
A document can have several parallel signatures: a new signature does not invalidate the existing ones. Sign the already signed file again, then check each signature. The index of the signatures starts at 0.
XadesSignature first = new XadesSignature("serial number");
first.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\manager.pfx", "123456");
first.ApplyDigitalSignature("invoice.xml", "invoice-signed.xml");
XadesSignature second = new XadesSignature("serial number");
second.DigitalSignatureCertificate = DigitalCertificate.LoadCertificate(@"d:\accountant.pfx", "123456");
second.ApplyDigitalSignature("invoice-signed.xml", "invoice-signed.xml"); // the output can be the input file
XadesSignature verifier = new XadesSignature("serial number");
int count = verifier.GetNumberOfSignatures("invoice-signed.xml");
for (int i = 0; i < count; i++)
Console.WriteLine("Signature " + (i + 1) + ": " + verifier.VerifyDigitalSignature("invoice-signed.xml", i) + ", signer: "
+ verifier.GetDigitalSignatureCertificate("invoice-signed.xml", i).GetNameInfo(X509NameType.SimpleName, false));
(X509NameType is in the namespace System.Security.Cryptography.X509Certificates.)
A changed document
If the document is modified after the signature, the verification returns False. For example, after the total of an invoice is edited from 1250.00 to 9250.00:
Console.WriteLine("Valid: " + new XadesSignature("serial number").VerifyDigitalSignature("invoice-changed.xml"));
// Valid: False
16.6 More options of the signature
These options are not in the window of XML Signer. They add information to the signature when a regulation or the receiver requires it.
// the commitment declared by the signer: approval, origin, receipt...
signature.CommitmentType = XadesCommitmentType.ProofOfApproval;
// the place where the signature was created
signature.SignatureProductionPlace = new XadesProductionPlace { City = "Bucharest", CountryName = "Romania" };
// an explicit signature policy: identifier (OID or URI), digest of the policy document, the algorithm of the digest, the address of the policy
signature.SetSignaturePolicyInformation("2.16.724.1.3.1.1.2.1.9", policyHash, "SHA256", "https://example.com/policy.pdf");
16.7 How the signature looks
The signature is added at the end of the XML document. The values below are shortened. SigningTime, the certificate of the signer (SigningCertificateV2) and the format of the signed data are the signed XAdES properties; a time stamp (XAdES-B-T and above) is added as an additional property of the signature.
<Invoice>
<Number>INV-2026-001</Number>
<Customer>Demo Company</Customer>
<Total currency="EUR">1250.00</Total>
<Signature Id="Signature-97744c13a070b011" xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
<SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
<Reference Id="r-97744c13a070b011-1" URI=""> <!-- the document -->
...
<DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
<DigestValue>jakNhmN0...</DigestValue>
</Reference>
<Reference URI="#SignedProperties-97744c13a070b011" Type="http://uri.etsi.org/01903#SignedProperties">
... <!-- the XAdES properties -->
</Reference>
</SignedInfo>
<SignatureValue>4Wg+fhw5jb23...</SignatureValue>
<KeyInfo><X509Data><X509Certificate>MIIDCzCC...</X509Certificate></X509Data></KeyInfo>
<Object>
<xades:QualifyingProperties Target="#Signature-97744c13a070b011" xmlns:xades="http://uri.etsi.org/01903/v1.3.2#">
<xades:SignedProperties Id="SignedProperties-97744c13a070b011">
<xades:SignedSignatureProperties>
<xades:SigningTime>2026-09-30T17:40:22Z</xades:SigningTime>
<xades:SigningCertificateV2> ... </xades:SigningCertificateV2>
</xades:SignedSignatureProperties>
<xades:SignedDataObjectProperties>
<xades:DataObjectFormat ObjectReference="#r-97744c13a070b011-1">
<xades:MimeType>text/xml</xades:MimeType>
</xades:DataObjectFormat>
</xades:SignedDataObjectProperties>
</xades:SignedProperties>
</xades:QualifyingProperties>
</Object>
</Signature>
</Invoice>
16.8 Good to know
| Situation | What happens |
|---|---|
No valid serial number in new XadesSignature("...") | The library works in demonstration mode: it writes a message and waits 10 seconds before each signature and verification. |
HashAlgorithm.SHA1 | A NotSupportedException is thrown: SHA1 is not used for new XAdES signatures. Old SHA-1 signatures can still be verified. |
XAdES-T, -LT or -LTA without TimeStamping.ServerUrl | An ArgumentException is thrown: the time stamp server is required. |
DigitalSignatureCertificate not set | A NullReferenceException is thrown. |
| The signing fails | The output file is deleted (unless it is the input file), so you never keep a half-made signed document. |
| A detached signature where the output is the signed file | An ArgumentException is thrown: the signature file must be another file. |
The library has also a class for the older XMLDSig signatures. For new documents use XadesSignature: XAdES contains XMLDSig and adds the signing time, the signer's certificate, time stamps and long-term validation data.
17. Problems and solutions
| What you see | What to do |
|---|---|
| Windows protected your PC when you start the setup | Windows SmartScreen does not know the new setup file yet. Click More info and then Run anyway, if you downloaded the file from www.signfiles.com (section 2). |
| Invalid license code. | The serial number has 20 characters. Retype it exactly as you received it, without extra characters (section 3). |
| Digital certificate is not set. In order to add a signature on your documents, select a digital certificate. | Click Select the Digital Certificate... and choose a certificate (section 6). |
| The certificate of the smart card or USB token is not in the list | Connect the token and check that its middleware is installed. The certificate must be in the Windows Certificate Store: open certmgr.msc and look in Personal. If it is not there, use the options of the middleware that copy or register the certificates in the Windows store (section 6.2). Then open the certificate window again. |
| The digital certificate ... expired on ... An expired certificate cannot be used to sign documents. | Choose a valid certificate or renew yours with your provider. |
| The private key of the digital certificate cannot be found. | The certificate on the computer has no key to sign with. Import the full certificate (including the private key), or connect your USB token. |
| PFX digital signature certificate error ... | The PFX password is wrong, or the file is damaged. Retype the password in the certificate window. |
| The smart card or token PIN is rejected | Correct the PIN in the certificate window. The program will not keep trying with a wrong PIN, to protect the token. |
| The XAdES-T signatures require a time stamp server, but the Time Stamp Server URL is not valid. | Open Time Stamp Settings... and type a valid address (section 8). Also check your Internet connection. |
| The selected folder does not contain XML documents. | Pick a folder that contains .xml files. |
| The destination file for the signed document already exists. Would you like to overwrite the existing file? | Click Yes to replace it, or No and choose another file name. |
| XML Signer has expired. Would you like to purchase the registered version...? | The trial period ended. Register with your license code (section 3). |
| The batch command does nothing, or the result code is 2 | Read the message in the command window and the file errorlog.txt (section 12). The usual causes: a path that ends with a backslash inside quotes, a configuration file that does not exist, an expired certificate, or a program that is not registered. |
| Viewer: The document does not contain XML digital signatures. | The file was never signed (or is not the signed copy). Open the signed file instead. |
| Viewer: The XML signature is not valid | The document was changed after signing, or the signature is damaged. Get the original signed file again. |
| Library: the program waits 10 seconds and writes This is a demonstration of the digital signature software | The serial number of the library is missing or not valid. Write the serial number in new XadesSignature("...") (section 16). |
Library: NotSupportedException when you sign | The hash algorithm is SHA1, which is not used for new XAdES signatures. Use SHA256, SHA384 or SHA512. |
Visit www.signfiles.com or use the contact link shown in the registration window, www.signfiles.com/contact.
18. Glossary
| Term | In plain words |
|---|---|
| Digital signature | An electronic seal added to a document. It shows who signed and that the content was not changed. |
| Digital certificate | Your electronic identity card, issued by a certification authority. It contains your name and a key used to sign. |
| PFX file | A file (.pfx or .p12, the PKCS#12 format) that holds a certificate and its private key, protected by a password. |
| Windows Certificate Store (Microsoft Store) | The place where Windows keeps the certificates installed on the computer or available from tokens and smart cards. It is not the Microsoft Store of applications. Open it with certmgr.msc. |
| Private key | The secret part of your certificate. Only you should have it. It is what makes a signature yours. |
| Smart card / USB token | A small device that keeps your private key and signs inside it, so the key cannot be copied. It is protected by a PIN. |
| Middleware | The software delivered with a smart card or token (for example SafeNet Authentication Client). It lets Windows and the programs use the device, and usually adds its certificates to the Windows store. |
| HSM | Hardware Security Module: a device that keeps the keys of a company and signs on request. |
| CSP / KSP | Cryptographic Service Provider / Key Storage Provider: the component that manages the private key. Certificate Service Provider in XML Signer shows its name. |
| Windows SmartScreen | A protection of Windows that warns you about programs it does not know yet. A warning does not mean that the program is infected. |
| Hash (SHA256) | A short fingerprint of the document. If the document changes, the fingerprint changes. |
| XMLDSig | The general standard for XML signatures. |
| XAdES | The European standard that extends XMLDSig with signing time, signer information, time stamps and long-term validation data. |
| Enveloped / detached signature | An enveloped signature is written inside the XML document. A detached signature is a separate file that refers to the signed file. |
| Time stamp / TSA | A proof of time issued by a trusted independent service (Time Stamp Authority). |
| OCSP / CRL | Ways to ask the certification authority whether a certificate was cancelled (revoked). The answers can be stored in the signature. |
| Self-signed certificate | A certificate you create yourself. It works technically but nobody else trusts it. Use it only for tests. |
| Canonicalization | Normalizing the XML text (spaces, attribute order...) before signing so that harmless formatting differences do not break the signature. |
| Serial number (license code) | The code that registers XML Signer, received after the purchase. The Signature Library has its own serial number. |
| SignLib (Signature Library) | The .NET library on which XML Signer is built. It lets programs and PowerShell scripts create and verify the same signatures. |
| Batch signing | Signing many documents in one operation, or automatically, without a user, from the command line. |
19. Warning and disclaimer, trademarks
Every effort has been made to make this manual as complete and accurate as possible, but no warranty or fitness is implied. The information provided is on an “as is” basis. The author shall have neither liability nor responsibility to any person or entity with respect to any loss or damages arising from the information contained in this manual.
.NET, Windows, PowerShell, SmartScreen and Visual Studio are trademarks of Microsoft Corporation. All other trademarks are the property of their respective owners.