Sample code for 30+ languages & platforms
CkPython Requires Chilkat v11.0.0+

RSA SHA256 Signature using Private Key from Java Keystore

See more RSA Examples

Signs plaintext using RSA SHA256 using a key from a Java keystore.

Duplicatest this code:

KeyStore keystore; // key repository for keys containing signature certificate
String alias; // alias for the certificate in the key repository
String password; // password for the certificate's private key
String plaintext; // text being signed


Signature signature = Signature.getInstance("SHA256withRSA");
signature.initSign((PrivateKey) keystore.getKey(alias, password.toCharArray()));
signature.update(plaintext.getBytes("UTF-8"));
byte[] rsa_text= signature.sign();

Chilkat CkPython Downloads

CkPython
import sys
import chilkat

success = False

#  This requires the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

jks = chilkat.CkJavaKeyStore()

jksPassword = "secret"

#  Load the Java keystore from a file.  The JKS file password is used
#  to verify the keyed digest that is found at the very end of the keystore.
#  It verifies that the keystore has not been modified.
success = jks.LoadFile(jksPassword,"qa_data/jks/sample_secret.jks")
if (success == False):
    print(jks.lastErrorText())
    sys.exit()

#  Get the private key from the JKS.
#  The private key password may be different than the file password.
privKeyPassword = "secret"
caseSensitive = False
privKey = chilkat.CkPrivateKey()
success = jks.PrivateKeyOf(privKeyPassword,"some.alias",caseSensitive,privKey)
if (success == False):
    print(jks.lastErrorText())
    sys.exit()

#  Establish the RSA object and tell it to use the private key..
rsa = chilkat.CkRsa()

success = rsa.UsePrivateKey(privKey)
if (success == False):
    print(rsa.lastErrorText())
    sys.exit()

#  Indicate we'll be signing the utf-8 byte representation of the string..
rsa.put_Charset("utf-8")

#  Sign some plaintext using RSA-SHA256
binarySignature = chilkat.CkByteData()
plaintext = "this is the text to be signed"
success = rsa.SignString(plaintext,"SHA256",binarySignature)
if (rsa.get_LastMethodSuccess() == False):
    print(rsa.lastErrorText())
    sys.exit()

#  Alternatively, if the signature is desired in some encoded string form,
#  such as base64, base64-url, hex, etc.
rsa.put_EncodingMode("base64-url")
signatureStr = rsa.signStringENC(plaintext,"SHA256")
print("base64-url RSA signature: " + signatureStr)