Sample code for 30+ languages & platforms
Rust Requires Chilkat v11.0.0+

PKCS11 Export Public Key from HSM

See more PKCS11 Examples

Demonstrates how to export a public key from a smartcard or token.

Chilkat Rust Downloads

Rust

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

let pkcs11 = chilkat::Pkcs11::new();

// Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
// (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
pkcs11.set_shared_lib_path("C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll");

// Establish a logged-on session. (We can typically skip the login by passing an empty PIN if only working with public keys)
// Use your actual PIN here, or an empty string to skip login.
let pin = "0000".to_string();
let user_type = 1;
if pkcs11.quick_session(user_type, &pin).is_err() {
    println!("{}", pkcs11.last_error_text());
    return;
}

// Get the handle of the public key we wish to export.
// You can find public keys in many different ways.
// This example will search for a public key by label.

// Provide a template to find a PKCS11 object.
let json_template = chilkat::JsonObject::new();

// Find the public key with the label "Belgium eHealth".
let _ = json_template.update_string("class", "public_key");
let _ = json_template.update_string("label", "Belgium eHealth");

let pub_key_handle = pkcs11.find_object(&json_template);
if pub_key_handle == 0 {
    println!("{}", pkcs11.last_error_text());
    return;
}

// Export to a Chilkat public key object.
let pub_key = chilkat::PublicKey::new();
if pkcs11.export_public_key(pub_key_handle, &pub_key).is_err() {
    println!("{}", pkcs11.last_error_text());
    return;
}

// Get the public key as PKCS8 PEM.
println!("{}", pub_key.get_pem(false).unwrap_or_default());

let _ = pkcs11.logout();
let _ = pkcs11.close_session();