Sample code for 30+ languages & platforms
Java Requires Chilkat v10.1.2+

RSA Sign using Private Key of Certificate Type A3 (smart card / token)

Demonstrates RSA signing data using the private key of a certificate type A3 (smart card, token).

Note: This is a Windows-only example.

Chilkat Java Downloads

Java
import com.chilkatsoft.*;

public class ChilkatExample {

  static {
    try {
        System.loadLibrary("chilkat");
    } catch (UnsatisfiedLinkError e) {
      System.err.println("Native code library failed to load.\n" + e);
      System.exit(1);
    }
  }

  public static void main(String argv[])
  {
    boolean success = false;

    //  First get the A3 certificate that was installed on the Windows system.
    CkCertStore certStore = new CkCertStore();

    String thumbprint = "12c1dd8015f3f03f7b1fa619dc24e2493ca8b4b2";

    //  This is specific to Windows because it is opening the Windows Current-User certificate store.
    boolean bReadOnly = true;
    success = certStore.OpenCurrentUserStore(bReadOnly);
    if (success != true) {
        System.out.println(certStore.lastErrorText());
        return;
        }

    //  Find the certificate with the desired thumbprint
    //  (There are many ways to locate a certificate.  This example chooses to find by thumbprint.)
    CkJsonObject json = new CkJsonObject();
    json.UpdateString("thumbprint",thumbprint);

    CkCert cert = new CkCert();
    success = certStore.FindCert(json,cert);
    if (success == false) {
        System.out.println("Failed to find the certificate.");
        return;
        }

    System.out.println("Found: " + cert.subjectCN());

    CkRsa rsa = new CkRsa();

    //  Provide the cert's private key
    boolean bUsePrivateKey = true;
    success = rsa.SetX509Cert(cert,bUsePrivateKey);
    if (success != true) {
        System.out.println(rsa.lastErrorText());
        return;
        }

    //  Now we're ready to sign..
    CkByteData dataToSign = new CkByteData();
    CkByteData sigData = new CkByteData();

    //  Get bytes to be signed..
    CkFileAccess fac = new CkFileAccess();
    success = fac.ReadEntireFile("in.dat",dataToSign);

    success = rsa.SignBytes(dataToSign,"SHA-256",sigData);
    if (success != true) {
        System.out.println(rsa.lastErrorText());
        return;
        }

    System.out.println("Signature created.");
  }
}