OfficeIMO.Security
3.0.0
Prefix Reserved
dotnet add package OfficeIMO.Security --version 3.0.0
NuGet\Install-Package OfficeIMO.Security -Version 3.0.0
<PackageReference Include="OfficeIMO.Security" Version="3.0.0" />
<PackageVersion Include="OfficeIMO.Security" Version="3.0.0" />
<PackageReference Include="OfficeIMO.Security" />
paket add OfficeIMO.Security --version 3.0.0
#r "nuget: OfficeIMO.Security, 3.0.0"
#:package OfficeIMO.Security@3.0.0
#addin nuget:?package=OfficeIMO.Security&version=3.0.0
#tool nuget:?package=OfficeIMO.Security&version=3.0.0
OfficeIMO.Security
OfficeIMO.Security is the shared cryptographic protocol owner for OfficeIMO. It provides neutral CMS/PKCS#7,
S/MIME, RFC 3161, certificate-chain, and enveloped-data operations backed by Bouncy Castle.
It does not reference PDF, Email, Drawing, or another OfficeIMO format package. Format packages translate their own models to and from these neutral results.
dotnet add package OfficeIMO.Security
The package deliberately owns protocol orchestration, validation policy, bounded parsing, and stable result models. It does not invent cryptographic primitives, manage certificate stores, select recipients, or silently use network revocation services. Applications remain responsible for key custody and trust policy.
CMS signing and verification
using OfficeIMO.Security;
byte[] signature = CmsSignedDataSigner.SignDetached(content, signingCertificate);
CmsVerificationResult result = CmsSignedDataVerifier.VerifyDetached(signature, content);
foreach (CmsSignerVerificationResult signer in result.Signers) {
Console.WriteLine($"{signer.Subject}: {signer.SignatureStatus}, {signer.CertificateValidation.ChainStatus}");
}
Signing uses the platform RSA handle and does not export the private key. Verification supports RSA and ECDSA
signers, keeps mathematical signature, message digest, certificate trust, revocation, and timestamp outcomes
separate, and never enables network revocation implicitly.
EnvelopedData
byte[] envelope = CmsEnvelopedDataService.Encrypt(content, new[] { recipientCertificate });
CmsDecryptionResult decrypted = CmsEnvelopedDataService.Decrypt(envelope, recipientWithPrivateKey);
Recipient selection is exact and caller-owned. The current Bouncy Castle key-transport adapter requires an exportable
RSA private key for envelope decryption; a non-exportable key produces the stable
EnvelopePrivateKeyNotExportable finding instead of silently falling back or exporting key material elsewhere.
Rfc3161TimestampVerifier validates timestamp signatures, TSA certificate profiles, message imprints, caller trust
policy, and revocation as a separate neutral operation. TSA chain validation defaults to the token generation time;
callers can override that instant through CertificateValidationOptions.VerificationTime.
Dependency footprint
- External:
BouncyCastle.Cryptography2.x. - OfficeIMO: None. PDF and Email depend on Security; Security never depends on a format package.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 is compatible. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETFramework 4.7.2
- BouncyCastle.Cryptography (>= 2.6.2 && < 3.0.0)
-
.NETStandard 2.0
- BouncyCastle.Cryptography (>= 2.6.2 && < 3.0.0)
-
net10.0
- BouncyCastle.Cryptography (>= 2.6.2 && < 3.0.0)
-
net8.0
- BouncyCastle.Cryptography (>= 2.6.2 && < 3.0.0)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on OfficeIMO.Security:
| Package | Downloads |
|---|---|
|
OfficeIMO.Pdf
First-party PDF builder, reader, editor, renderer, and signature workflow for .NET. |
|
|
OfficeIMO.Email
Managed email and Outlook data engine for EML, MSG/OFT, TNEF, ICS, vCard, Mbox, PST/OST, OLM, EMLX, Maildir, and Offline Address Book artifacts. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 3.0.0 | 859 | 7/20/2026 |