Microsoft CNG with CMS/PKCS#7 signing nowhere to be found RRS feed

  • Question

  • The following page describes the Microsoft CNG features, including the term "CMS (S/MIME)":

    However, I have yet to find any documentation on using CNG to create a CMS (PKCS#7) signed structure.  Why doesn't CNG support CMS signing out of the box?  I understand that Crypto API does provide this via the CmsSigner class, but I cannot use that because it doesn't support Sha2 digests, nor does it seem to provide PSS padding support.

    Does Microsoft CNG provide any out-of-the-box support for CMS signatures?  If not, why does the page mentioned above say that it does?

    I need to ability to create a CMS signed structure using a Sha256 digest algorithm with PSS padding.

    Thank you,


    Friday, February 16, 2018 9:53 PM

All replies