Sample code for 30+ languages & platforms
Zig Requires Chilkat v10.1.3+

Yubikey RSA Encrypt/Decrypt

See more RSA Examples

Demonstrates how to do RSA decryption using a private key stored on a Yubikey (or other USB token or smartcard).

Note: RSA encryption uses the public key, which is freely exportable and does not need to occur on the token/smartcard.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes you have a certificate with private key on the Yubikey token.
    // When doing simple RSA encryption/decryption, we don't actually need the certificate,
    // but we'll be using the private key associated with the certificate.
    //
    // The sensitive/secret material that needs to be kept private is the private key.
    // The certificate itself and the public key can be freely shared.
    //

    // We're going to encrypt and decrypt 32-bytes of data.
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    try bd.appendEncoded("000102030405060708090A0B0C0D0E0F", "hex");
    try bd.appendEncoded("000102030405060708090A0B0C0D0E0F", "hex");

    // Let's get the desired cert.
    // For this example, a self-signed certificate with a 2048-bit RSA key was generated in slot 9A.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    // Force Chilkat to use PKCS11 over ScMinidriver (if on Windows) and Apple Keychain (if on MacOS)
    cert.setUncommonOptions("NoScMinidriver,NoAppleKeychain");

    cert.setSmartCardPin("123456");

    cert.loadFromSmartcard("cn=chilkat_test_2048") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // RSA encrypt using the public key.
    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();

    // Provide the RSA object with the certificate on the Yubkey.
    rsa.setX509Cert(cert, true) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    // RSA encrypt using the public key.
    var use_private_key: bool = false;
    rsa.encryptBd(bd, use_private_key) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("RSA Encrypted Output in Hex:\n", .{});
    std.debug.print("{s}\n", .{try bd.getEncoded(alloc, "hex")});

    // Now let's decrypt, using the private key on the Yubikey.
    use_private_key = true;
    rsa.decryptBd(bd, use_private_key) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("RSA Decrypted Output in Hex:\n", .{});
    std.debug.print("{s}\n", .{try bd.getEncoded(alloc, "hex")});
}