Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

PKCS11 Import an Existing RSA Public Key onto the HSM

See more PKCS11 Examples

Demonstrates how to import an existing RSA Public Key onto a smart card or token.

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

  final pkcs11 = CkPkcs11();

  // Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
  // (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
  pkcs11.sharedLibPath = 'C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll';

  // Establish a logged-on session.
  final pin = '0000';
  final userType = 1;
  try {
    pkcs11.quickSession(userType, pin);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Generate a new 2048-bit RSA key.
  final rsa = CkRsa();
  final privKey = CkPrivateKey();
  try {
    rsa.genKey(2048, privKey);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Get the public key information as XML, so we can access the modulus and exponent.
  final xml = CkXml();
  final pubKey = CkPublicKey();
  privKey.toPublicKey(pubKey);
  xml.loadXml(pubKey.getXml());

  final attrs = CkJsonObject();
  // Specify the type of object, and the type of key.
  attrs.updateString('class', 'CKO_PUBLIC_KEY');
  attrs.updateString('key_type', 'CKK_RSA');
  // Add an optional label if desired.
  attrs.updateString('label', 'RSA Public Key 1');
  // Allow the key to be use for verify, wrapping, and encryption operations.
  attrs.updateBool('verify', true);
  attrs.updateBool('wrap', true);
  attrs.updateBool('encrypt', true);

  // Make this a session-only public key.
  // To store the public key on the token so that it persists after the PKCS11 session, set token = true.
  attrs.updateBool('token', false);

  // Provide the RSA public key material
  attrs.updateString('modulus', xml.getChildContent('Modulus'));
  attrs.updateString('public_exponent', xml.getChildContent('Exponent'));

  // Create the RSA public key.
  // Returns the PKCS11 object handle of the created key.
  final objHandle = pkcs11.createPkcs11Object(attrs);
  if (objHandle == 0) {
    print(pkcs11.lastErrorText);
    print('Failed.');
  } else {
    print('PKCS11 object handle = $objHandle');
    print('Successfully imported an RSA key..');
  }

  pkcs11.logout();
  pkcs11.closeSession();
}