I am trying to sign a CSR with a local certificate using pkijs library but CA always returns an error: Failed to parse the PKIOperation request.
I also think sign method in pkijs only returns the signature and not the enveloped data with it as my enveloped data size is quite larger than signed data size.
Here is the code I am using to sign the data:
public signScepCsr(csr: ArrayBuffer, signingCert: Certificate, privateKey: any) {
let sequence = Promise.resolve();
//region Create a message digest
const crypto = getCrypto();
sequence.then(() => {
let certSigned = new SignedData({
version: 1,
encapContentInfo: new EncapsulatedContentInfo({
eContentType: this.envelopedDataOid
}),
signerInfos: [new SignerInfo({
version: 1,
sid: new IssuerAndSerialNumber({
issuer: signingCert.issuer,
serialNumber: signingCert.serialNumber
}),
messageType: 19,
transactionID: Guid.create().toString(),
})],
certificaes: [signingCert]
});
// Sign the CSR buffer with local certificate private key.
return certSigned.sign(privateKey, 0, this.hashAlg, csr);
});
let result = '';
return sequence.then((result) => {
let r2 = result as SignedData;
let certSignedSchema = r2.toSchema(true);
let signedContent = new ContentInfo({
contentType: this.signedDataOid,
content: certSignedSchema
});
let finalSignedSchema = signedContent.toSchema();
//region Make length of some elements in "indefinite form"
finalSignedSchema.lenBlock.isIndefiniteForm = true;
var block1 = finalSignedSchema.valueBlock.value[1];
block1.lenBlock.isIndefiniteForm = true;
var block2 = block1.valueBlock.value[0];
block2.lenBlock.isIndefiniteForm = true;
let signedContentBuffer = finalSignedSchema.toBER(false);
let resultStr = window.btoa(String.fromCharCode.apply(null, new Uint8Array(signedContentBuffer)));
return resultStr;
},
() => Promise.reject('Failed to successfully sign the CSR.'));
}
Is there any suggestion?