Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

PKCS11 Import a Private Key onto the HSM

See more PKCS11 Examples

Demonstrates how to import an existing RSA private key onto the smartcard/token. The imported key is a token object, meaning it stays on the HSM and exists beyond the end of the PKCS11 session.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

  final pkcs11 = CkPkcs11();

  // Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
  // (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
  pkcs11.sharedLibPath = 'C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll';

  // Establish a logged-on session.
  final pin = '0000';
  final userType = 1;
  try {
    pkcs11.quickSession(userType, pin);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Let's import a certificate's private key onto the HSM.
  // First, we'll load the certificate from a .pfx (also known as .p12), which is a file format
  // that also includes the certificate's private key.
  final cert = CkCert();
  try {
    cert.loadPfxFile('qa_data/pfx/ehealth.fgov.be_testing.p12', 'p12_password');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Let's get the certificate's private key.
  final privKey = CkPrivateKey();
  try {
    cert.getPrivateKey(privKey);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Build a PKCS11 template to provide additional information about the key to be imported.
  final jsonTemplate = CkJsonObject();

  // Indicate that the key is to be stored on the token.  It is NOT a session object.
  jsonTemplate.updateBool('token', true);

  // Indicate that the key can be used for signing.
  jsonTemplate.updateBool('sign', true);

  // Provide an arbitrary ID and label (anything you want).
  // The information in the ID and/or label provides one means for finding the key in future PKCS11 sessions.
  jsonTemplate.updateString('id_hex', '010203040A0B0C0D0E0F');
  jsonTemplate.updateString('label', 'ehealth private key');

  // Import the key.  The private key handle is returned on success.  Otherwise 0 is returned.
  // If our only task for now is to simply import the key, we can ignore the returned handle, 
  // other than to check for success/failure.  Otherwise, the handle can be used in other PKCS11 operations.
  // This example just creates the key and does not use the returned handle.
  final keyHandle = pkcs11.importPrivateKey(privKey, jsonTemplate);
  if (keyHandle == 0) {
    print(pkcs11.lastErrorText);
  } else {
    print('key handle = $keyHandle');
    print('Successfully imported a private key onto the HSM.');
  }

  pkcs11.logout();
  pkcs11.closeSession();
}