Zig
Zig
PKCS11 Find Private Key by Label
See more PKCS11 Examples
Demonstrates how to find a private key based on a user-specified label.Note: This example requires Chilkat v9.5.0.96 or later.
Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.
const pkcs11 = try chilkat.Pkcs11.init();
defer pkcs11.deinit();
// Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
// For example:
pkcs11.setSharedLibPath("C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS11.dll");
// Use your HSM's PIN.
const pin = "0000";
// Normal user = 1
const user_type = 1;
// Establish a logged-on user session with the HSM.
pkcs11.quickSession(user_type, pin) catch {
std.debug.print("{s}\n", .{try pkcs11.getLastErrorText(alloc)});
return;
};
// Provide a template to find a PKCS11 object.
const json_template = try chilkat.JsonObject.init();
defer json_template.deinit();
// Find an RSA private key with the label "MySshKey".
// Here's an example of how the key was originally imported:
// PKCS11 Import SSH Key
json_template.updateString("class", "private_key") catch {};
json_template.updateString("key_type", "rsa") catch {};
json_template.updateString("label", "MySshKey") catch {};
const priv_key_handle = pkcs11.findObject(json_template);
if (priv_key_handle == 0) {
std.debug.print("{s}\n", .{try pkcs11.getLastErrorText(alloc)});
return;
}
// The private key handle is only valid during the PKCS11 session.
// If you wish to use the private key in another PKCS11 session,
// you'll first need to find it. See:
std.debug.print("private key handle: {d}\n", .{priv_key_handle});
// Do whatever you wish with the private key handle...
// ...
// ...
pkcs11.logout() catch {};
pkcs11.closeSession() catch {};
}