Sample code for 30+ languages & platforms
Dart Requires Chilkat v10.1.3+

Yubikey RSA Encrypt/Decrypt

See more RSA Examples

Demonstrates how to do RSA decryption using a private key stored on a Yubikey (or other USB token or smartcard).

Note: RSA encryption uses the public key, which is freely exportable and does not need to occur on the token/smartcard.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example assumes you have a certificate with private key on the Yubikey token.
  // When doing simple RSA encryption/decryption, we don't actually need the certificate,
  // but we'll be using the private key associated with the certificate.
  // 
  // The sensitive/secret material that needs to be kept private is the private key.
  // The certificate itself and the public key can be freely shared.
  // 

  // We're going to encrypt and decrypt 32-bytes of data.
  final bd = CkBinData();
  bd.appendEncoded('000102030405060708090A0B0C0D0E0F', 'hex');
  bd.appendEncoded('000102030405060708090A0B0C0D0E0F', 'hex');

  // Let's get the desired cert.
  // For this example, a self-signed certificate with a 2048-bit RSA key was generated in slot 9A.
  final cert = CkCert();

  // Force Chilkat to use PKCS11 over ScMinidriver (if on Windows) and Apple Keychain (if on MacOS)
  cert.uncommonOptions = 'NoScMinidriver,NoAppleKeychain';

  cert.smartCardPin = '123456';

  try {
    cert.loadFromSmartcard('cn=chilkat_test_2048');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // RSA encrypt using the public key.
  final rsa = CkRsa();

  // Provide the RSA object with the certificate on the Yubkey.
  try {
    rsa.setX509Cert(cert, true);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // RSA encrypt using the public key.
  var usePrivateKey = false;
  try {
    rsa.encryptBd(bd, usePrivateKey);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('RSA Encrypted Output in Hex:');
  print(bd.getEncoded('hex'));

  // Now let's decrypt, using the private key on the Yubikey.
  usePrivateKey = true;
  try {
    rsa.decryptBd(bd, usePrivateKey);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('RSA Decrypted Output in Hex:');
  print(bd.getEncoded('hex'));
}