Xbase++ Requires Chilkat v11.0.0+
Xbase++
PKCS11 Export Public Key from HSM
See more PKCS11 Examples
Demonstrates how to export a public key from a smartcard or token.Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oPkcs11
LOCAL cPin
LOCAL nUserType
LOCAL oJsonTemplate
LOCAL nPubKeyHandle
LOCAL oPubKey
nSuccess := 0
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.
oPkcs11 := CreateObject("Chilkat.Pkcs11")
// Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
// (The format of the path will change with the operating system. Obviously, "C:/" is not used on non-Windows systems.
oPkcs11:SharedLibPath := "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll"
// Establish a logged-on session. (We can typically skip the login by passing an empty PIN if only working with public keys)
// Use your actual PIN here, or an empty string to skip login.
cPin := "0000"
nUserType := 1
nSuccess := oPkcs11:QuickSession(nUserType, cPin)
IF (nSuccess == 0)
? oPkcs11:LastErrorText
oPkcs11:destroy()
RETURN
ENDIF
// Get the handle of the public key we wish to export.
// You can find public keys in many different ways.
// This example will search for a public key by label.
// Provide a template to find a PKCS11 object.
oJsonTemplate := CreateObject("Chilkat.JsonObject")
// Find the public key with the label "Belgium eHealth".
oJsonTemplate:UpdateString("class", "public_key")
oJsonTemplate:UpdateString("label", "Belgium eHealth")
nPubKeyHandle := oPkcs11:FindObject(oJsonTemplate)
IF (nPubKeyHandle == 0)
? oPkcs11:LastErrorText
oPkcs11:destroy()
oJsonTemplate:destroy()
RETURN
ENDIF
// Export to a Chilkat public key object.
oPubKey := CreateObject("Chilkat.PublicKey")
nSuccess := oPkcs11:ExportPublicKey(nPubKeyHandle, oPubKey)
IF (nSuccess == 0)
? oPkcs11:LastErrorText
oPkcs11:destroy()
oJsonTemplate:destroy()
oPubKey:destroy()
RETURN
ENDIF
// Get the public key as PKCS8 PEM.
? oPubKey:GetPem(0)
oPkcs11:Logout()
oPkcs11:CloseSession()
oPkcs11:destroy()
oJsonTemplate:destroy()
oPubKey:destroy()