Sample code for 30+ languages & platforms
Delphi DLL Requires Chilkat v10.1.2+

RSA Sign using Private Key of Certificate Type A3 (smart card / token)

Demonstrates RSA signing data using the private key of a certificate type A3 (smart card, token).

Note: This is a Windows-only example.

Chilkat Delphi DLL Downloads

Delphi DLL
var
success: Boolean;
certStore: HCkCertStore;
thumbprint: PWideChar;
bReadOnly: Boolean;
json: HCkJsonObject;
cert: HCkCert;
rsa: HCkRsa;
bUsePrivateKey: Boolean;
dataToSign: HCkByteData;
sigData: HCkByteData;
fac: HCkFileAccess;

begin
success := False;

//  First get the A3 certificate that was installed on the Windows system.
certStore := CkCertStore_Create();

thumbprint := '12c1dd8015f3f03f7b1fa619dc24e2493ca8b4b2';

//  This is specific to Windows because it is opening the Windows Current-User certificate store.
bReadOnly := True;
success := CkCertStore_OpenCurrentUserStore(certStore,bReadOnly);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkCertStore__lastErrorText(certStore));
    Exit;
  end;

//  Find the certificate with the desired thumbprint
//  (There are many ways to locate a certificate.  This example chooses to find by thumbprint.)
json := CkJsonObject_Create();
CkJsonObject_UpdateString(json,'thumbprint',thumbprint);

cert := CkCert_Create();
success := CkCertStore_FindCert(certStore,json,cert);
if (success = False) then
  begin
    Memo1.Lines.Add('Failed to find the certificate.');
    Exit;
  end;

Memo1.Lines.Add('Found: ' + CkCert__subjectCN(cert));

rsa := CkRsa_Create();

//  Provide the cert's private key
bUsePrivateKey := True;
success := CkRsa_SetX509Cert(rsa,cert,bUsePrivateKey);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkRsa__lastErrorText(rsa));
    Exit;
  end;

//  Now we're ready to sign..
dataToSign := CkByteData_Create();
sigData := CkByteData_Create();

//  Get bytes to be signed..
fac := CkFileAccess_Create();
success := CkFileAccess_ReadEntireFile(fac,'in.dat',dataToSign);

success := CkRsa_SignBytes(rsa,dataToSign,'SHA-256',sigData);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkRsa__lastErrorText(rsa));
    Exit;
  end;

Memo1.Lines.Add('Signature created.');

CkCertStore_Dispose(certStore);
CkJsonObject_Dispose(json);
CkCert_Dispose(cert);
CkRsa_Dispose(rsa);
CkByteData_Dispose(dataToSign);
CkByteData_Dispose(sigData);
CkFileAccess_Dispose(fac);