Sample code for 30+ languages & platforms
Zig

RSA Sign using a Private Key on a USB Token or Smartcard

See more Apple Keychain Examples

Create an RSA signature using a private key stored on a USB token or smartcard.

Note: On MacOS and iOS, this example requires Chilkat v10.1.2 or later when the Apple Keychain is used as the underlying means to do the signing.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
    // this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.

    // Chilkat automatically detects and determines the way in which the HSM is used,
    // which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.

    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    // Set the token/smartcard PIN prior to loading.
    cert.setSmartCardPin("123456");

    // Specify the certificate by its common name.
    cert.loadFromSmartcard("cn=chilkat-rsa-2048") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Signing with cert: {s}\n", .{try cert.getSubjectCN(alloc)});

    // Create data to be hashed and signed.
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    var i: i32 = 0;
    i = 0;
    while (i <= 100) : (i += 1) {
        bd.appendEncoded("000102030405060708090A0B0C0D0E0F", "hex") catch {};
    }

    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();

    // Use the certificate's private key for signing.
    rsa.setX509Cert(cert, true) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // Sign the SHA-256 hash of the contents of bd.
    const bd_sig = try chilkat.BinData.init();
    defer bd_sig.deinit();
    rsa.signBd(bd, "sha256", bd_sig) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // The RSA signature is equal in length to the size of the RSA key.
    std.debug.print("Output signature size in bits = {d}\n", .{bd_sig.getNumBytes() * 8});

    // We can save the signature for later verification..
    bd_sig.writeFile("rsaSignatures/test1.sig") catch {};

    // See the example to verify the RSA signature:
    // Verfies an RSA Signature
}