v1.0 · .NET 10 · Production-proven

GİB e-Ledger signing, without Ma3Api.

XAdES-BES signing that matches the Ma3Api wire format bit for bit, plus EU DSS-equivalent validation. RSA + ECDSA, USB token + Windows CSP + PFX. The only dependency: .NET 10.

170+ unit tests0 warnings · 0 errors4 library modules~150 ms / signature
Features

A production-proven design behind a lean API.

Every wire-format decision was verified against real GİB rejection and acceptance cases. Source comments carry date + company + tax ID references — they are the regression armour.

XAdES-BES generator

SignedProperties, Reference, SignedInfo, KeyInfo — all in the order and format GİB tooling accepts. Plain c14n, ECDSA-DER, LF-only output.

3 key sources

PKCS#11 (USB e-Seal), Windows CSP/CNG (RDP-friendly), PFX (testing). Transparent selection behind a single ISigningKey abstraction.

RSA + ECDSA

P-256/SHA-256, P-384/SHA-384, P-521/SHA-512 — NIST strength matching is automatic. e-Seal version 3 and version 4 work side by side.

Two-layer validation

Fast cryptographic Verify + EU DSS-equivalent DssEquivalentValidator. The 7 building blocks are reported separately.

KamuSM root chain

Certificate chain validation with the embedded kamusm-trusted-cas.json. New CA → update the JSON and restart.

170+ xUnit tests

XAdES round-trip, XmlRepairer, log patterns, certificate utilities. The suite passes in under a second in CI.

Schematron + XSD

GİB edefter.xsd + 4 schematron rule sets (journal, ledger, berat, report) through SchematronRunner (Saxon-HE).

XmlRepairer

Fixes common defects: encoding, period bounds, MimeType. Automatic clean-up before signing.

RDP / VM compatible

When PKCS#11 cannot see an RDP-redirected card, WindowsCspSigningKey sees the card store. One line of code is the only difference.

Comparison

mm.erp vs. the alternatives.

Ma3Api: GİB's older Java reference. GİB Viewer: validation only, no signing. Hand-written solutions: very common, but they break on wire-format details.

mm.erp Ma3Api (Java) GİB Viewer Hand-written .NET
Platform .NET 10 (Windows + Linux)Java 8+ (heavyweight)Java GUI applicationVaries
Signature generation ✓ XAdES-BES ✓ XAdES-BES ✗ ~ partial
Signature validation ✓ Fast + DSS-equivalent~ Basic ✓ Advanced ~ Basic
USB e-Seal (PKCS#11) ✓ ✓ — ~ Hard
Windows CSP (RDP-friendly) ✓ ✗ — ~
RSA + ECDSA automatic hash matching ✓ P-256/384/521 ~ Fixed — ✗
ECDSA-DER encoding (GİB compliance) ✓ ✓ — ✗ Frequent failure
Plain c14n (NOT WithComments) ✓ Fixed ✓ — ✗ Frequent failure
LF-only output (CRLF normalised) ✓ ✓ — ✗ Breaks on Windows
KamuSM root CA chain validation ✓ Embedded JSON ~ Manual ✓ ✗
Schematron (Saxon-HE) ✓ Built in ✓ ✓ ✗
XSD schema validation ✓ ✓ ✓ ~
7 EU DSS-equivalent building blocks ✓ ✗ ~ Visual ✗
Signing time / TSP validation ✓ RFC3161 ✓ ✓ ✗
XmlRepairer (encoding, period bounds) ✓ Automatic ✗ — ✗
CLI tool ✓ SignerCli ~ Command line— —
NuGet integration ✓ Direct reference ✗ jar import — ~
Latency (per signature) ~150 ms ~600 ms — Varies
Unit test count 170+ ~ Few — Mostly none
Production approval (real GİB) ✓ 2025-2026 cases ✓ Historical ✓ ✗
Licence Internal use GİB proprietary GİB proprietary —
Note: "~" means partially supported / requires manual effort. "✗" means the feature is missing or the tool does not perform that function. "—" means not applicable (e.g. GİB Viewer does not create signatures).
Architecture

Thin layers, clear responsibilities.

4 .NET projects + a CLI. Each layer does one thing; the production experience behind it is documented in comment blocks.

core

MegaeDefter4Net.Crypto

ISigningKey abstraction · XAdesBesSigner engine · c14n · digest · pretty-print.

wrapper

MegaeDefter4Net.Signing

EDefterSigner file/byte wrapper · PfxSigningKey · CRLF→LF normalisation.

hardware

MegaeDefter4Net.SmartCard

Pkcs11SigningKey (akisp11.dll) · WindowsCspSigningKey (CryptoAPI/CNG) · certificate selection ranking.

validation

MegaeDefter4Net.Validation

DssEquivalentValidator · XAdesEnvelopeValidator · XsdValidator · SchematronRunner · XmlRepairer.

RSA-SHA256 RSA-SHA384 RSA-SHA512 ECDSA-P256-SHA256 ECDSA-P384-SHA384 ECDSA-P521-SHA512 XML C14N 1.0 XAdES-BES RFC3161 TSP PKCS#11 v2.40 CryptoAPI / CNG
Quick start

Sign in three lines.

The API is lean. Reference the library, pick your key and call SignFile.

C# — PFX (testing)
using var key = new PfxSigningKey("test.pfx", "1234");
var signer = new EDefterSigner(key, new XAdesSignerOptions
    { ClaimedRole = "Supplier" });
signer.SignFile("yevmiye.xml", "yevmiye.signed.xml");
C# — USB token (production)
using var key = new Pkcs11SigningKey(
    driverPath: CardDriverRegistry.AutoDetect(),
    tokenSerial: null,
    pin: "123456");
new EDefterSigner(key).SignFile("yev.xml", "yev.signed.xml");
C# — Validation
var doc = new XmlDocument { PreserveWhitespace = true };
doc.Load("yev.signed.xml");
// Fast cryptographic check
bool ok = XAdesBesSigner.Verify(doc);

// Full EU DSS-equivalent report
var report = new DssEquivalentValidator().Validate(doc, "yev.signed.xml");
CLI — SignerCli
# PFX
SignerCli sign-pfx --pfx test.pfx --password 1234 \
    --in yev.xml --out yev.signed.xml --role Supplier

# USB token
SignerCli sign-p11 --in yev.xml --out yev.signed.xml --pin 123456

# Windows store (RDP)
SignerCli sign-csp --in yev.xml --out yev.signed.xml --vkn 1234567890

# Validate (DSS mode)
SignerCli verify --in yev.signed.xml --mode dss
Frequently asked questions

Ma3Api, e-signatures and financial e-seals.

Short answers to the most common questions. For details, see the documentation page (in Turkish).

Is there an alternative to Ma3Api?

Yes. mm.erp is written entirely in .NET 10, has no dependency on Ma3Api, and produces XAdES-BES signatures that are bit-for-bit compatible and accepted in production by the GİB e-Ledger web service (Ma3Api validator). .NET 10 is the only dependency; no Java runtime is needed. Production experience is documented in source comments with date + company + tax ID references.

Which library should I use for e-signatures on .NET?

The mm.erp e-signature library supports RSA + ECDSA (P-256 / P-384 / P-521) with automatic hash matching. Every GİB-critical wire-format decision — XAdES-BES envelopes, plain c14n, ECDSA-DER encoding and LF-only output — is production-proven and verified against real rejection and acceptance cases.

What do I need to use a financial e-seal?

A USB e-Seal token issued by KamuSM, the card management tool (AKİS / SafeNet / E-Tugra), the 6-digit card PIN and the Pkcs11SigningKey class. CardDriverRegistry.AutoDetect() finds the driver file (e.g. akisp11.dll) automatically.

Can the e-seal be used over RDP?

Yes. PKCS#11 drivers cannot see an RDP-redirected smart card — but the Windows Smart Card Service can. The mm.erp WindowsCspSigningKey class works from the Windows certificate store (CSP/CNG) and uses the redirected token transparently over RDP. Switching between the two paths is a one-line code change.

How is a signed e-Ledger file validated?

There are two layers: XAdesBesSigner.Verify performs a fast cryptographic check; DssEquivalentValidator performs full chain validation with the 7 EU DSS-equivalent building blocks (FormatChecking, IdentificationOfSigningCertificate, X509CertificateValidation, CryptographicVerification, SignatureAcceptanceValidation, AlgorithmObsolescenceValidation, ValidationContextInitialization). The KamuSM root CA list (kamusm-trusted-cas.json) is embedded in the library.

Which certificate types are supported?

RSA (1024+ bit, SHA-256/384/512) and ECDSA (P-256 / P-384 / P-521, with curve-matched SHA). e-Seal version 3 (P-384 ECDSA) and version 4 (RSA-2048) work together without issues. The hash algorithm is chosen automatically from the key strength, following NIST guidance.

How is it integrated into ERP / accounting software?

Three ways: (1) add a NuGet reference and use the EDefterSigner class directly, (2) shell out to the SignerCli.exe command-line tool, (3) send HTTP requests to a Windows service. Option 1 is the fastest (~150 ms / signature); option 3 provides isolation for legacy VB.NET projects.

How are licensing and support provided?

The library is developed and maintained for internal use by ERP İnternet ve Yazılım Hizmetleri Tic. Ltd. Şti. For 24/7 phone and WhatsApp support, see the Contact section.

Leave Ma3Api behind and take control.

The only dependency: .NET 10. Every wire-format detail is production-proven. The documentation is concise.

Contact

Have a question?

We provide support around the clock. Reach us through whichever channel suits you best.

Request a demo or a quote

Leave your details and we will get back to you within 24 hours.

Your details are used only to reply to you and are never shared with third parties.

or contact us directly

ERP İnternet ve Yazılım Hizmetleri Tic. Ltd. Şti.

📍 PERPA Tic. Merkezi A Blok, Kat 12 No: 1924, Şişli / İstanbul

💬 Message us on WhatsApp
Email Contact email address Shown as an image to prevent spam
Social Facebook · Instagram