Sample code for 30+ languages & platforms
Objective-C

RSA Sign String using Private Key of Certificate Type A3 (smart card / token)

See more RSA Examples

Demonstrates RSA signing a string using the private key of a certificate type A3 (smart card, token).

Note: This is a Windows-only example.

Chilkat Objective-C Downloads

Objective-C
#import <CkoCertStore.h>
#import <NSString.h>
#import <CkoJsonObject.h>
#import <CkoCert.h>
#import <CkoRsa.h>

BOOL success = NO;

//  First get the A3 certificate that was installed on the Windows system.
CkoCertStore *certStore = [[CkoCertStore alloc] init];

NSString *thumbprint = @"12c1dd8015f3f03f7b1fa619dc24e2493ca8b4b2";

//  This is specific to Windows because it is opening the Windows Current-User certificate store.
BOOL bReadOnly = YES;
success = [certStore OpenCurrentUserStore: bReadOnly];
if (success != YES) {
    NSLog(@"%@",certStore.LastErrorText);
    return;
}

//  Find the certificate with the desired thumbprint
//  (There are many ways to locate a certificate.  This example chooses to find by thumbprint.)
CkoJsonObject *json = [[CkoJsonObject alloc] init];
[json UpdateString: @"thumbprint" value: thumbprint];

CkoCert *cert = [[CkoCert alloc] init];
success = [certStore FindCert: json cert: cert];
if (success == NO) {
    NSLog(@"%@",@"Failed to find the certificate.");
    return;
}

NSLog(@"%@%@",@"Found: ",cert.SubjectCN);

CkoRsa *rsa = [[CkoRsa alloc] init];

//  Provide the cert's private key
BOOL bUsePrivateKey = YES;
success = [rsa SetX509Cert: cert usePrivateKey: bUsePrivateKey];
if (success != YES) {
    NSLog(@"%@",rsa.LastErrorText);
    return;
}

//  Return the RSA signature in base64 encoded form.
rsa.EncodingMode = @"base64";

//  Sign the utf-8 byte representation of the string.
rsa.Charset = @"utf-8";

//  You can also choose other hash algorithms, such as SHA-1.
NSString *sigBase64 = [rsa SignStringENC: @"text to sign" hashAlg: @"SHA-256"];
if (rsa.LastMethodSuccess != YES) {
    NSLog(@"%@",rsa.LastErrorText);
    return;
}

NSLog(@"%@%@",@"Base64 signature: ",sigBase64);