Sample code for 30+ languages & platforms
Lazarus Pascal

RSA Sign an Encoded Hash

See more RSA Examples

Demonstrates signing a hash (e.g., SHA256) provided as an encoded string (e.g., base64 or hex).

Chilkat Lazarus Pascal Downloads

Lazarus Pascal
program ChilkatDemo;

// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.

{$IFDEF FPC}
  {$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}

uses
  {$IFDEF UNIX}
  cthreads,
  {$ENDIF}
  SysUtils,
  CkDllLoader,
  Chilkat.BinData,
  Chilkat.Rsa,
  Chilkat.Cert;

// ---------------------------------------------------------------------------

procedure RunDemo;
var
  success: Boolean;
  cert: TCert;
  bd: TBinData;
  i: Integer;
  rsa: TRsa;
  sha256_base64: string;
  rsaSig_base64: string;

begin
  success := False;

  //  Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
  //  this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.

  //  Chilkat automatically detects and determines the way in which the HSM is used,
  //  which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.

  cert := TCert.Create;

  //  Set the token/smartcard PIN prior to loading.
  cert.SmartCardPin := '123456';

  //  Specify the certificate by its common name.
  success := cert.LoadFromSmartcard('cn=chilkat-rsa-2048');
  if (success = False) then
    begin
      WriteLn(cert.LastErrorText);
      Exit;
    end;

  WriteLn('Signing with the private key for this cert: ' + cert.SubjectCN);

  //  Create data to be hashed and signed.
  bd := TBinData.Create;

  for i := 0 to 100 do
    begin
      bd.AppendEncoded('000102030405060708090A0B0C0D0E0F','hex');
    end;

  rsa := TRsa.Create;

  //  Use the certificate's private key for signing.
  success := rsa.SetX509Cert(cert,True);
  if (success = False) then
    begin
      WriteLn(rsa.LastErrorText);
      Exit;
    end;

  //  We'll first compute the hash and then pass the encoded hash to be signed.
  sha256_base64 := bd.GetHash('sha256','base64');
  WriteLn('sha256 hash in base64 format: ' + sha256_base64);

  //  Pass in the base64 hash and return a base64 signature.
  rsa.EncodingMode := 'base64';
  rsaSig_base64 := rsa.SignHashENC(sha256_base64,'sha256');
  if (success = False) then
    begin
      WriteLn(rsa.LastErrorText);
      Exit;
    end;

  WriteLn('RSA signature as base64: ' + rsaSig_base64);


  cert.Free;
  bd.Free;
  rsa.Free;

end;

// ---------------------------------------------------------------------------

begin

  try
    RunDemo;
  except
    on E: Exception do
      WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
  end;

  WriteLn;
  {$IFDEF MSWINDOWS}
  WriteLn('Press Enter to exit...');
  ReadLn;
  {$ENDIF}
end.