using System.Security.Cryptography.X509Certificates; namespace GB5Shared.DigitalSignature { public interface IDigitalSignatureService { // Hashes `data` internally, then signs the hash — matches GenerateSignature.cs's // existing contract (callers supply raw data to be signed). Task SignDataAsync(string thumbprint, byte[] data, CancellationToken ct); // Signs an ALREADY-COMPUTED hash directly (no internal re-hashing) — required by // callers like iText7's PdfSigner, which computes the PDF byte-range digest itself and // must pass that exact digest through to the RSA signing operation unchanged. Task SignHashAsync(string thumbprint, byte[] hash, CancellationToken ct); // Returns the certificate (public chain, no private key required) — used by consumers // that need to embed the signing chain (e.g. iText7 PdfSigner) alongside the raw signature. Task GetSigningCertificateAsync(string thumbprint, CancellationToken ct); } }