C Requires Chilkat v10.1.2+
C
RSA Sign using Private Key of Certificate Type A3 (smart card / token)
Demonstrates RSA signing data using the private key of a certificate type A3 (smart card, token).Note: This is a Windows-only example.
Chilkat C Downloads
#include <C_CkCertStore.h>
#include <C_CkJsonObject.h>
#include <C_CkCert.h>
#include <C_CkRsa.h>
#include <C_CkByteData.h>
#include <C_CkFileAccess.h>
void ChilkatSample(void)
{
BOOL success;
HCkCertStore certStore;
const char *thumbprint;
BOOL bReadOnly;
HCkJsonObject json;
HCkCert cert;
HCkRsa rsa;
BOOL bUsePrivateKey;
HCkByteData dataToSign;
HCkByteData sigData;
HCkFileAccess fac;
success = FALSE;
// First get the A3 certificate that was installed on the Windows system.
certStore = CkCertStore_Create();
thumbprint = "12c1dd8015f3f03f7b1fa619dc24e2493ca8b4b2";
// This is specific to Windows because it is opening the Windows Current-User certificate store.
bReadOnly = TRUE;
success = CkCertStore_OpenCurrentUserStore(certStore,bReadOnly);
if (success != TRUE) {
printf("%s\n",CkCertStore_lastErrorText(certStore));
CkCertStore_Dispose(certStore);
return;
}
// Find the certificate with the desired thumbprint
// (There are many ways to locate a certificate. This example chooses to find by thumbprint.)
json = CkJsonObject_Create();
CkJsonObject_UpdateString(json,"thumbprint",thumbprint);
cert = CkCert_Create();
success = CkCertStore_FindCert(certStore,json,cert);
if (success == FALSE) {
printf("Failed to find the certificate.\n");
CkCertStore_Dispose(certStore);
CkJsonObject_Dispose(json);
CkCert_Dispose(cert);
return;
}
printf("Found: %s\n",CkCert_subjectCN(cert));
rsa = CkRsa_Create();
// Provide the cert's private key
bUsePrivateKey = TRUE;
success = CkRsa_SetX509Cert(rsa,cert,bUsePrivateKey);
if (success != TRUE) {
printf("%s\n",CkRsa_lastErrorText(rsa));
CkCertStore_Dispose(certStore);
CkJsonObject_Dispose(json);
CkCert_Dispose(cert);
CkRsa_Dispose(rsa);
return;
}
// Now we're ready to sign..
dataToSign = CkByteData_Create();
sigData = CkByteData_Create();
// Get bytes to be signed..
fac = CkFileAccess_Create();
success = CkFileAccess_ReadEntireFile(fac,"in.dat",dataToSign);
success = CkRsa_SignBytes(rsa,dataToSign,"SHA-256",sigData);
if (success != TRUE) {
printf("%s\n",CkRsa_lastErrorText(rsa));
CkCertStore_Dispose(certStore);
CkJsonObject_Dispose(json);
CkCert_Dispose(cert);
CkRsa_Dispose(rsa);
CkByteData_Dispose(dataToSign);
CkByteData_Dispose(sigData);
CkFileAccess_Dispose(fac);
return;
}
printf("Signature created.\n");
CkCertStore_Dispose(certStore);
CkJsonObject_Dispose(json);
CkCert_Dispose(cert);
CkRsa_Dispose(rsa);
CkByteData_Dispose(dataToSign);
CkByteData_Dispose(sigData);
CkFileAccess_Dispose(fac);
}