Rust
Rust
RSA Sign using a Private Key on a USB Token or Smartcard
See more Apple Keychain Examples
Create an RSA signature using a private key stored on a USB token or smartcard.Note: On MacOS and iOS, this example requires Chilkat v10.1.2 or later when the Apple Keychain is used as the underlying means to do the signing.
Chilkat Rust Downloads
// Assuming the smartcard/USB token is installed with the correct drivers from the manufacturer,
// this code can work on multiple platforms including Windows, MacOS, Linux, and iOS.
// Chilkat automatically detects and determines the way in which the HSM is used,
// which can be by PKCS11, Apple Keychain, Microsoft CNG / Crypto API, or ScMinidriver.
let cert = chilkat::Cert::new();
// Set the token/smartcard PIN prior to loading.
cert.set_smart_card_pin("123456");
// Specify the certificate by its common name.
if cert.load_from_smartcard("cn=chilkat-rsa-2048").is_err() {
println!("{}", cert.last_error_text());
return;
}
println!("Signing with cert: {}", cert.subject_cn());
// Create data to be hashed and signed.
let bd = chilkat::BinData::new();
for i in 0..=100 {
let _ = bd.append_encoded("000102030405060708090A0B0C0D0E0F", "hex");
}
let rsa = chilkat::Rsa::new();
// Use the certificate's private key for signing.
if rsa.set_x509_cert(&cert, true).is_err() {
println!("{}", rsa.last_error_text());
return;
}
// Sign the SHA-256 hash of the contents of bd.
let bd_sig = chilkat::BinData::new();
if rsa.sign_bd(&bd, "sha256", &bd_sig).is_err() {
println!("{}", rsa.last_error_text());
return;
}
// The RSA signature is equal in length to the size of the RSA key.
println!("Output signature size in bits = {}", bd_sig.num_bytes() * 8);
// We can save the signature for later verification..
let _ = bd_sig.write_file("rsaSignatures/test1.sig");
// See the example to verify the RSA signature:
// Verfies an RSA Signature