Sample code for 30+ languages & platforms
Xbase++

RSA Sign using a Private Key on a USB Token or Smartcard

See more Apple Keychain Examples

Create an RSA signature using a private key stored on a USB token or smartcard.

Note: On MacOS and iOS, this example requires Chilkat v10.1.2 or later when the Apple Keychain is used as the underlying means to do the signing.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCert
LOCAL oBd
LOCAL i
LOCAL oRsa
LOCAL oBdSig

nSuccess := 0

//  Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
//  this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.

//  Chilkat automatically detects and determines the way in which the HSM is used,
//  which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.

oCert := CreateObject("Chilkat.Cert")

//  Set the token/smartcard PIN prior to loading.
oCert:SmartCardPin := "123456"

//  Specify the certificate by its common name.
nSuccess := oCert:LoadFromSmartcard("cn=chilkat-rsa-2048")
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oCert:destroy()
    RETURN
ENDIF

? "Signing with cert: " + oCert:SubjectCN

//  Create data to be hashed and signed.
oBd := CreateObject("Chilkat.BinData")

FOR i := 0 TO 100
    oBd:AppendEncoded("000102030405060708090A0B0C0D0E0F", "hex")
NEXT

oRsa := CreateObject("Chilkat.Rsa")

//  Use the certificate's private key for signing.
nSuccess := oRsa:SetX509Cert(oCert, 1)
IF (nSuccess == 0)
    ? oRsa:LastErrorText
    oCert:destroy()
    oBd:destroy()
    oRsa:destroy()
    RETURN
ENDIF

//  Sign the SHA-256 hash of the contents of bd.
oBdSig := CreateObject("Chilkat.BinData")
nSuccess := oRsa:SignBd(oBd, "sha256", oBdSig)
IF (nSuccess == 0)
    ? oRsa:LastErrorText
    oCert:destroy()
    oBd:destroy()
    oRsa:destroy()
    oBdSig:destroy()
    RETURN
ENDIF

//  The RSA signature is equal in length to the size of the RSA key.
? "Output signature size in bits = " + Str(oBdSig:NumBytes * 8)

//  We can save the signature for later verification..
oBdSig:WriteFile("rsaSignatures/test1.sig")

//  See the example to verify the RSA signature:
//  Verfies an RSA Signature

oCert:destroy()
oBd:destroy()
oRsa:destroy()
oBdSig:destroy()