XAdES-BES generator
SignedProperties, Reference, SignedInfo, KeyInfo — all in the order and format GİB tooling accepts. Plain c14n, ECDSA-DER, LF-only output.
XAdES-BES signing that matches the Ma3Api wire format bit for bit, plus EU DSS-equivalent validation. RSA + ECDSA, USB token + Windows CSP + PFX. The only dependency: .NET 10.
Every wire-format decision was verified against real GİB rejection and acceptance cases. Source comments carry date + company + tax ID references — they are the regression armour.
SignedProperties, Reference, SignedInfo, KeyInfo — all in the order and format GİB tooling accepts. Plain c14n, ECDSA-DER, LF-only output.
PKCS#11 (USB e-Seal), Windows CSP/CNG (RDP-friendly), PFX (testing). Transparent selection behind a single ISigningKey abstraction.
P-256/SHA-256, P-384/SHA-384, P-521/SHA-512 — NIST strength matching is automatic. e-Seal version 3 and version 4 work side by side.
Fast cryptographic Verify + EU DSS-equivalent DssEquivalentValidator. The 7 building blocks are reported separately.
Certificate chain validation with the embedded kamusm-trusted-cas.json. New CA → update the JSON and restart.
XAdES round-trip, XmlRepairer, log patterns, certificate utilities. The suite passes in under a second in CI.
GİB edefter.xsd + 4 schematron rule sets (journal, ledger, berat, report) through SchematronRunner (Saxon-HE).
Fixes common defects: encoding, period bounds, MimeType. Automatic clean-up before signing.
When PKCS#11 cannot see an RDP-redirected card, WindowsCspSigningKey sees the card store. One line of code is the only difference.
Ma3Api: GİB's older Java reference. GİB Viewer: validation only, no signing. Hand-written solutions: very common, but they break on wire-format details.
| mm.erp | Ma3Api (Java) | GİB Viewer | Hand-written .NET | |
|---|---|---|---|---|
| Platform | .NET 10 (Windows + Linux) | Java 8+ (heavyweight) | Java GUI application | Varies |
| Signature generation | ✓ XAdES-BES | ✓ XAdES-BES | ✗ | ~ partial |
| Signature validation | ✓ Fast + DSS-equivalent | ~ Basic | ✓ Advanced | ~ Basic |
| USB e-Seal (PKCS#11) | ✓ | ✓ | — | ~ Hard |
| Windows CSP (RDP-friendly) | ✓ | ✗ | — | ~ |
| RSA + ECDSA automatic hash matching | ✓ P-256/384/521 | ~ Fixed | — | ✗ |
| ECDSA-DER encoding (GİB compliance) | ✓ | ✓ | — | ✗ Frequent failure |
| Plain c14n (NOT WithComments) | ✓ Fixed | ✓ | — | ✗ Frequent failure |
| LF-only output (CRLF normalised) | ✓ | ✓ | — | ✗ Breaks on Windows |
| KamuSM root CA chain validation | ✓ Embedded JSON | ~ Manual | ✓ | ✗ |
| Schematron (Saxon-HE) | ✓ Built in | ✓ | ✓ | ✗ |
| XSD schema validation | ✓ | ✓ | ✓ | ~ |
| 7 EU DSS-equivalent building blocks | ✓ | ✗ | ~ Visual | ✗ |
| Signing time / TSP validation | ✓ RFC3161 | ✓ | ✓ | ✗ |
| XmlRepairer (encoding, period bounds) | ✓ Automatic | ✗ | — | ✗ |
| CLI tool | ✓ SignerCli | ~ Command line | — | — |
| NuGet integration | ✓ Direct reference | ✗ jar import | — | ~ |
| Latency (per signature) | ~150 ms | ~600 ms | — | Varies |
| Unit test count | 170+ | ~ Few | — | Mostly none |
| Production approval (real GİB) | ✓ 2025-2026 cases | ✓ Historical | ✓ | ✗ |
| Licence | Internal use | GİB proprietary | GİB proprietary | — |
4 .NET projects + a CLI. Each layer does one thing; the production experience behind it is documented in comment blocks.
ISigningKey abstraction · XAdesBesSigner engine · c14n · digest · pretty-print.
EDefterSigner file/byte wrapper · PfxSigningKey · CRLF→LF normalisation.
Pkcs11SigningKey (akisp11.dll) · WindowsCspSigningKey (CryptoAPI/CNG) · certificate selection ranking.
DssEquivalentValidator · XAdesEnvelopeValidator · XsdValidator · SchematronRunner · XmlRepairer.
The API is lean. Reference the library, pick your key and call SignFile.
using var key = new PfxSigningKey("test.pfx", "1234");
var signer = new EDefterSigner(key, new XAdesSignerOptions
{ ClaimedRole = "Supplier" });
signer.SignFile("yevmiye.xml", "yevmiye.signed.xml");
using var key = new Pkcs11SigningKey(
driverPath: CardDriverRegistry.AutoDetect(),
tokenSerial: null,
pin: "123456");
new EDefterSigner(key).SignFile("yev.xml", "yev.signed.xml");
var doc = new XmlDocument { PreserveWhitespace = true };
doc.Load("yev.signed.xml");
// Fast cryptographic check
bool ok = XAdesBesSigner.Verify(doc);
// Full EU DSS-equivalent report
var report = new DssEquivalentValidator().Validate(doc, "yev.signed.xml");
# PFX
SignerCli sign-pfx --pfx test.pfx --password 1234 \
--in yev.xml --out yev.signed.xml --role Supplier
# USB token
SignerCli sign-p11 --in yev.xml --out yev.signed.xml --pin 123456
# Windows store (RDP)
SignerCli sign-csp --in yev.xml --out yev.signed.xml --vkn 1234567890
# Validate (DSS mode)
SignerCli verify --in yev.signed.xml --mode dss
Short answers to the most common questions. For details, see the documentation page (in Turkish).
Yes. mm.erp is written entirely in .NET 10, has no dependency on Ma3Api, and produces XAdES-BES signatures that are bit-for-bit compatible and accepted in production by the GİB e-Ledger web service (Ma3Api validator). .NET 10 is the only dependency; no Java runtime is needed. Production experience is documented in source comments with date + company + tax ID references.
The mm.erp e-signature library supports RSA + ECDSA (P-256 / P-384 / P-521) with automatic hash matching. Every GİB-critical wire-format decision — XAdES-BES envelopes, plain c14n, ECDSA-DER encoding and LF-only output — is production-proven and verified against real rejection and acceptance cases.
A USB e-Seal token issued by KamuSM, the card management tool (AKİS / SafeNet / E-Tugra), the 6-digit card PIN and the Pkcs11SigningKey class. CardDriverRegistry.AutoDetect() finds the driver file (e.g. akisp11.dll) automatically.
Yes. PKCS#11 drivers cannot see an RDP-redirected smart card — but the Windows Smart Card Service can. The mm.erp WindowsCspSigningKey class works from the Windows certificate store (CSP/CNG) and uses the redirected token transparently over RDP. Switching between the two paths is a one-line code change.
There are two layers: XAdesBesSigner.Verify performs a fast cryptographic check; DssEquivalentValidator performs full chain validation with the 7 EU DSS-equivalent building blocks (FormatChecking, IdentificationOfSigningCertificate, X509CertificateValidation, CryptographicVerification, SignatureAcceptanceValidation, AlgorithmObsolescenceValidation, ValidationContextInitialization). The KamuSM root CA list (kamusm-trusted-cas.json) is embedded in the library.
RSA (1024+ bit, SHA-256/384/512) and ECDSA (P-256 / P-384 / P-521, with curve-matched SHA). e-Seal version 3 (P-384 ECDSA) and version 4 (RSA-2048) work together without issues. The hash algorithm is chosen automatically from the key strength, following NIST guidance.
Three ways: (1) add a NuGet reference and use the EDefterSigner class directly, (2) shell out to the SignerCli.exe command-line tool, (3) send HTTP requests to a Windows service. Option 1 is the fastest (~150 ms / signature); option 3 provides isolation for legacy VB.NET projects.
The library is developed and maintained for internal use by ERP İnternet ve Yazılım Hizmetleri Tic. Ltd. Şti. For 24/7 phone and WhatsApp support, see the Contact section.
The only dependency: .NET 10. Every wire-format detail is production-proven. The documentation is concise.
We provide support around the clock. Reach us through whichever channel suits you best.
or contact us directly
📍 PERPA Tic. Merkezi A Blok, Kat 12 No: 1924, Şişli / İstanbul