Zig
Zig
RSA Sign using a Private Key on a USB Token or Smartcard
See more Apple Keychain Examples
Create an RSA signature using a private key stored on a USB token or smartcard.Note: On MacOS and iOS, this example requires Chilkat v10.1.2 or later when the Apple Keychain is used as the underlying means to do the signing.
Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
// this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.
// Chilkat automatically detects and determines the way in which the HSM is used,
// which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.
const cert = try chilkat.Cert.init();
defer cert.deinit();
// Set the token/smartcard PIN prior to loading.
cert.setSmartCardPin("123456");
// Specify the certificate by its common name.
cert.loadFromSmartcard("cn=chilkat-rsa-2048") catch {
std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
return;
};
std.debug.print("Signing with cert: {s}\n", .{try cert.getSubjectCN(alloc)});
// Create data to be hashed and signed.
const bd = try chilkat.BinData.init();
defer bd.deinit();
var i: i32 = 0;
i = 0;
while (i <= 100) : (i += 1) {
bd.appendEncoded("000102030405060708090A0B0C0D0E0F", "hex") catch {};
}
const rsa = try chilkat.Rsa.init();
defer rsa.deinit();
// Use the certificate's private key for signing.
rsa.setX509Cert(cert, true) catch {
std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
return;
};
// Sign the SHA-256 hash of the contents of bd.
const bd_sig = try chilkat.BinData.init();
defer bd_sig.deinit();
rsa.signBd(bd, "sha256", bd_sig) catch {
std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
return;
};
// The RSA signature is equal in length to the size of the RSA key.
std.debug.print("Output signature size in bits = {d}\n", .{bd_sig.getNumBytes() * 8});
// We can save the signature for later verification..
bd_sig.writeFile("rsaSignatures/test1.sig") catch {};
// See the example to verify the RSA signature:
// Verfies an RSA Signature
}