Sample code for 30+ languages & platforms
PureBasic Requires Chilkat v11.0.0+

RSA SHA256 Signature using Private Key from Java Keystore

See more RSA Examples

Signs plaintext using RSA SHA256 using a key from a Java keystore.

Duplicatest this code:

KeyStore keystore; // key repository for keys containing signature certificate
String alias; // alias for the certificate in the key repository
String password; // password for the certificate's private key
String plaintext; // text being signed


Signature signature = Signature.getInstance("SHA256withRSA");
signature.initSign((PrivateKey) keystore.getKey(alias, password.toCharArray()));
signature.update(plaintext.getBytes("UTF-8"));
byte[] rsa_text= signature.sign();

Chilkat PureBasic Downloads

PureBasic
IncludeFile "CkJavaKeyStore.pb"
IncludeFile "CkRsa.pb"
IncludeFile "CkPrivateKey.pb"

Procedure ChilkatExample()

    success.i = 0

    ;  This requires the Chilkat API to have been previously unlocked.
    ;  See Global Unlock Sample for sample code.

    jks.i = CkJavaKeyStore::ckCreate()
    If jks.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    jksPassword.s = "secret"

    ;  Load the Java keystore from a file.  The JKS file password is used
    ;  to verify the keyed digest that is found at the very end of the keystore.
    ;  It verifies that the keystore has not been modified.
    success = CkJavaKeyStore::ckLoadFile(jks,jksPassword,"qa_data/jks/sample_secret.jks")
    If success = 0
        Debug CkJavaKeyStore::ckLastErrorText(jks)
        CkJavaKeyStore::ckDispose(jks)
        ProcedureReturn
    EndIf

    ;  Get the private key from the JKS.
    ;  The private key password may be different than the file password.
    privKeyPassword.s = "secret"
    caseSensitive.i = 0
    privKey.i = CkPrivateKey::ckCreate()
    If privKey.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    success = CkJavaKeyStore::ckPrivateKeyOf(jks,privKeyPassword,"some.alias",caseSensitive,privKey)
    If success = 0
        Debug CkJavaKeyStore::ckLastErrorText(jks)
        CkJavaKeyStore::ckDispose(jks)
        CkPrivateKey::ckDispose(privKey)
        ProcedureReturn
    EndIf

    ;  Establish the RSA object and tell it to use the private key..
    rsa.i = CkRsa::ckCreate()
    If rsa.i = 0
        Debug "Failed to create object."
        ProcedureReturn
    EndIf

    success = CkRsa::ckUsePrivateKey(rsa,privKey)
    If success = 0
        Debug CkRsa::ckLastErrorText(rsa)
        CkJavaKeyStore::ckDispose(jks)
        CkPrivateKey::ckDispose(privKey)
        CkRsa::ckDispose(rsa)
        ProcedureReturn
    EndIf

    ;  Indicate we'll be signing the utf-8 byte representation of the string..
    CkRsa::setCkCharset(rsa, "utf-8")

    ;  Sign some plaintext using RSA-SHA256
ERROR - PureBasic is an array language
    plaintext.s = "this is the text to be signed"
    binarySignature = CkRsa::ckSignString(rsa,plaintext,"SHA256")
    If CkRsa::ckLastMethodSuccess(rsa) = 0
        Debug CkRsa::ckLastErrorText(rsa)
        CkJavaKeyStore::ckDispose(jks)
        CkPrivateKey::ckDispose(privKey)
        CkRsa::ckDispose(rsa)
        ProcedureReturn
    EndIf

    ;  Alternatively, if the signature is desired in some encoded string form,
    ;  such as base64, base64-url, hex, etc.
    CkRsa::setCkEncodingMode(rsa, "base64-url")
    signatureStr.s = CkRsa::ckSignStringENC(rsa,plaintext,"SHA256")
    Debug "base64-url RSA signature: " + signatureStr


    CkJavaKeyStore::ckDispose(jks)
    CkPrivateKey::ckDispose(privKey)
    CkRsa::ckDispose(rsa)


    ProcedureReturn
EndProcedure