Sample code for 30+ languages & platforms
PureBasic

RSA Sign an Encoded Hash

See more RSA Examples

Demonstrates signing a hash (e.g., SHA256) provided as an encoded string (e.g., base64 or hex).

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkBinData.pb"
IncludeFile "CkCert.pb"
IncludeFile "CkRsa.pb"

Procedure ChilkatExample()

    success.i = 0

    ; Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
    ; this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.

    ; Chilkat automatically detects and determines the way in which the HSM is used,
    ; which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.

    cert.i = CkCert::ckCreate()
    If cert.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ; Set the token/smartcard PIN prior to loading.
    CkCert::setCkSmartCardPin(cert, "123456")

    ; Specify the certificate by its common name.
    success = CkCert::ckLoadFromSmartcard(cert,"cn=chilkat-rsa-2048")
    If success = 0
        Debug CkCert::ckLastErrorText(cert)
        CkCert::ckDispose(cert)
        ProcedureReturn
    EndIf

    Debug "Signing with the private key for this cert: " + CkCert::ckSubjectCN(cert)

    ; Create data to be hashed and signed.
    bd.i = CkBinData::ckCreate()
    If bd.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    i.i
    For i = 0 To 100
        CkBinData::ckAppendEncoded(bd,"000102030405060708090A0B0C0D0E0F","hex")
    Next

    rsa.i = CkRsa::ckCreate()
    If rsa.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    ; Use the certificate's private key for signing.
    success = CkRsa::ckSetX509Cert(rsa,cert,1)
    If success = 0
        Debug CkRsa::ckLastErrorText(rsa)
        CkCert::ckDispose(cert)
        CkBinData::ckDispose(bd)
        CkRsa::ckDispose(rsa)
        ProcedureReturn
    EndIf

    ; We'll first compute the hash and then pass the encoded hash to be signed.
    sha256_base64.s = CkBinData::ckGetHash(bd,"sha256","base64")
    Debug "sha256 hash in base64 format: " + sha256_base64

    ; Pass in the base64 hash and return a base64 signature.
    CkRsa::setCkEncodingMode(rsa, "base64")
    rsaSig_base64.s = CkRsa::ckSignHashENC(rsa,sha256_base64,"sha256")
    If success = 0
        Debug CkRsa::ckLastErrorText(rsa)
        CkCert::ckDispose(cert)
        CkBinData::ckDispose(bd)
        CkRsa::ckDispose(rsa)
        ProcedureReturn
    EndIf

    Debug "RSA signature as base64: " + rsaSig_base64


    CkCert::ckDispose(cert)
    CkBinData::ckDispose(bd)
    CkRsa::ckDispose(rsa)


    ProcedureReturn
EndProcedure