Sample code for 30+ languages & platforms
React Native Requires Chilkat v11.0.0+

PKCS11 Import an Existing RSA Public Key onto the HSM

See more PKCS11 Examples

Demonstrates how to import an existing RSA Public Key onto a smart card or token.

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat React Native Downloads

React Native
import { JsonObject, Pkcs11, PrivateKey, PublicKey, Rsa, Xml } from '@chilkat/react-native'

function chilkatExample() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

  const pkcs11 = new Pkcs11();

  // Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
  // (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
  pkcs11.sharedLibPath = 'C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll';

  // Establish a logged-on session.
  const pin = '0000';
  const userType = 1;
  try {
    pkcs11.quickSession(userType, pin);
  } catch {
    console.log(pkcs11.lastErrorText);
    return;
  }

  // Generate a new 2048-bit RSA key.
  const rsa = new Rsa();
  const privKey = new PrivateKey();
  try {
    rsa.genKey(2048, privKey);
  } catch {
    console.log(rsa.lastErrorText);
    return;
  }

  // Get the public key information as XML, so we can access the modulus and exponent.
  const xml = new Xml();
  const pubKey = new PublicKey();
  privKey.toPublicKey(pubKey);
  xml.loadXml(pubKey.getXml());

  const attrs = new JsonObject();
  // Specify the type of object, and the type of key.
  attrs.updateString('class', 'CKO_PUBLIC_KEY');
  attrs.updateString('key_type', 'CKK_RSA');
  // Add an optional label if desired.
  attrs.updateString('label', 'RSA Public Key 1');
  // Allow the key to be use for verify, wrapping, and encryption operations.
  attrs.updateBool('verify', true);
  attrs.updateBool('wrap', true);
  attrs.updateBool('encrypt', true);

  // Make this a session-only public key.
  // To store the public key on the token so that it persists after the PKCS11 session, set token = true.
  attrs.updateBool('token', false);

  // Provide the RSA public key material
  attrs.updateString('modulus', xml.getChildContent('Modulus'));
  attrs.updateString('public_exponent', xml.getChildContent('Exponent'));

  // Create the RSA public key.
  // Returns the PKCS11 object handle of the created key.
  const objHandle = pkcs11.createPkcs11Object(attrs);
  if (objHandle === 0) {
    console.log(pkcs11.lastErrorText);
    console.log('Failed.');
  } else {
    console.log(`PKCS11 object handle = ${objHandle}`);
    console.log('Successfully imported an RSA key..');
  }

  pkcs11.logout();
  pkcs11.closeSession();
}