Sample code for 30+ languages & platforms
React Native Requires Chilkat v10.1.3+

Yubikey RSA Encrypt/Decrypt

See more RSA Examples

Demonstrates how to do RSA decryption using a private key stored on a Yubikey (or other USB token or smartcard).

Note: RSA encryption uses the public key, which is freely exportable and does not need to occur on the token/smartcard.

Chilkat React Native Downloads

React Native
import { BinData, Cert, Rsa } from '@chilkat/react-native'

function chilkatExample() {
  // This example assumes you have a certificate with private key on the Yubikey token.
  // When doing simple RSA encryption/decryption, we don't actually need the certificate,
  // but we'll be using the private key associated with the certificate.
  // 
  // The sensitive/secret material that needs to be kept private is the private key.
  // The certificate itself and the public key can be freely shared.
  // 

  // We're going to encrypt and decrypt 32-bytes of data.
  const bd = new BinData();
  bd.appendEncoded('000102030405060708090A0B0C0D0E0F', 'hex');
  bd.appendEncoded('000102030405060708090A0B0C0D0E0F', 'hex');

  // Let's get the desired cert.
  // For this example, a self-signed certificate with a 2048-bit RSA key was generated in slot 9A.
  const cert = new Cert();

  // Force Chilkat to use PKCS11 over ScMinidriver (if on Windows) and Apple Keychain (if on MacOS)
  cert.uncommonOptions = 'NoScMinidriver,NoAppleKeychain';

  cert.smartCardPin = '123456';

  try {
    cert.loadFromSmartcard('cn=chilkat_test_2048');
  } catch {
    console.log(cert.lastErrorText);
    return;
  }

  // RSA encrypt using the public key.
  const rsa = new Rsa();

  // Provide the RSA object with the certificate on the Yubkey.
  try {
    rsa.setX509Cert(cert, true);
  } catch {
    console.log(rsa.lastErrorText);
    return;
  }

  // RSA encrypt using the public key.
  let usePrivateKey = false;
  try {
    rsa.encryptBd(bd, usePrivateKey);
  } catch {
    console.log(rsa.lastErrorText);
    return;
  }

  console.log('RSA Encrypted Output in Hex:');
  console.log(bd.getEncoded('hex'));

  // Now let's decrypt, using the private key on the Yubikey.
  usePrivateKey = true;
  try {
    rsa.decryptBd(bd, usePrivateKey);
  } catch {
    console.log(rsa.lastErrorText);
    return;
  }

  console.log('RSA Decrypted Output in Hex:');
  console.log(bd.getEncoded('hex'));
}