Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(SQL Server) Create JWS Using Private Key on a Smart CardSee more JSON Web Signatures (JWS) ExamplesCreates and validates a JSON Web Signature (JWS) using the private key associated with a certificate on a smart card.
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls. -- CREATE PROCEDURE ChilkatSample AS BEGIN DECLARE @hr int DECLARE @iTmp0 int -- Important: Do not use nvarchar(max). See the warning about using nvarchar(max). DECLARE @sTmp0 nvarchar(4000) -- This requires the Chilkat API to have been previously unlocked. -- See Global Unlock Sample for sample code. -- Load the certificate from a smart card. DECLARE @cert int -- Use "Chilkat_9_5_0.Cert" for versions of Chilkat < 10.0.0 EXEC @hr = sp_OACreate 'Chilkat.Cert', @cert OUT IF @hr <> 0 BEGIN PRINT 'Failed to create ActiveX component' RETURN END DECLARE @success int EXEC sp_OAMethod @cert, 'LoadFromSmartcard', @success OUT, '' IF @success = 0 BEGIN EXEC sp_OAGetProperty @cert, 'LastErrorText', @sTmp0 OUT PRINT @sTmp0 EXEC @hr = sp_OADestroy @cert RETURN END -- Note: Chilkat provides many different ways to load a certificate from a smartcard or USB token, -- such as selecting a certificate if the card contains multiple certificates with private keys, -- or working with lower-level PKCS11 or ScMinidriver API's (both of which Chilkat provides). -- If the associated private key was present on the smartcard, then you can simply -- get it from the Chilkat cert object: DECLARE @privKey int EXEC sp_OAMethod @cert, 'ExportPrivateKey', @privKey OUT EXEC sp_OAGetProperty @cert, 'LastMethodSuccess', @iTmp0 OUT IF @iTmp0 = 0 BEGIN EXEC sp_OAGetProperty @cert, 'LastErrorText', @sTmp0 OUT PRINT @sTmp0 EXEC @hr = sp_OADestroy @cert RETURN END -- You can check the key type to make sure it's RSA. -- This will output "rsa" if the key is RSA. EXEC sp_OAGetProperty @privKey, 'KeyType', @sTmp0 OUT PRINT 'Key type = ' + @sTmp0 -- Create the JWS Protected Header DECLARE @jwsProtHdr int -- Use "Chilkat_9_5_0.JsonObject" for versions of Chilkat < 10.0.0 EXEC @hr = sp_OACreate 'Chilkat.JsonObject', @jwsProtHdr OUT EXEC sp_OAMethod @jwsProtHdr, 'AppendString', @success OUT, 'alg', 'RS256' DECLARE @jws int -- Use "Chilkat_9_5_0.Jws" for versions of Chilkat < 10.0.0 EXEC @hr = sp_OACreate 'Chilkat.Jws', @jws OUT -- Set the protected header: DECLARE @signatureIndex int SELECT @signatureIndex = 0 EXEC sp_OAMethod @jws, 'SetProtectedHeader', @success OUT, @signatureIndex, @jwsProtHdr -- Set the RSA key: EXEC sp_OAMethod @jws, 'SetPrivateKey', @success OUT, @signatureIndex, @privKey -- Set the payload. DECLARE @bIncludeBom int SELECT @bIncludeBom = 0 DECLARE @payloadStr nvarchar(4000) SELECT @payloadStr = 'In our village, folks say God crumbles up the old moon into stars.' EXEC sp_OAMethod @jws, 'SetPayload', @success OUT, @payloadStr, 'utf-8', @bIncludeBom -- Create the JWS -- By default, the compact serialization is used. DECLARE @jwsCompact nvarchar(4000) EXEC sp_OAMethod @jws, 'CreateJws', @jwsCompact OUT EXEC sp_OAGetProperty @jws, 'LastMethodSuccess', @iTmp0 OUT IF @iTmp0 <> 1 BEGIN EXEC sp_OAGetProperty @jws, 'LastErrorText', @sTmp0 OUT PRINT @sTmp0 EXEC @hr = sp_OADestroy @privKey EXEC @hr = sp_OADestroy @cert EXEC @hr = sp_OADestroy @jwsProtHdr EXEC @hr = sp_OADestroy @jws RETURN END PRINT 'JWS: ' + @jwsCompact -- sample output: -- JWS: eyJhbGciOiJQUzI1NiJ9.SW4gb3VyIHZpbGxhZ2UsIGZvbGtzIHNheSBHb2QgY3J1bWJsZXMgdXAgdGhlIG9sZCBtb29uIGludG8gc3RhcnMu.TRWhwRo5dMv9-8OzrInfJTwmUGYgjLfHk8lqF072ND-FmLWEBnUTOpY8oJXp8FdWw2SalbdOeNlrtlJjwk4XK8Ql2iJ_2qMCtxsvLPhKBOqFoAF4aBvTOEDVJDxf0DaBSiydEEtfTVV2iwBcjWabu5J2XieR5y7QZQtuHsn7T3qKBvCcCejN3Y2oqAT3qMHvu1fTms1r_91wBn_K7Wjd9UkZ1n02qQcUHJznR_OF2BgN7_KWIDAF9ZS9keoju2NPpPelO4yxa2XUPnehY3G7dHKoCxUEQR4d2Xc5voqDASTVCDqQS4PVOZdvT3Ein6-SanAlCwbWBbkvT8g6-5PImQ -- Now load the JWS, validate, and recover the original text. DECLARE @jws2 int -- Use "Chilkat_9_5_0.Jws" for versions of Chilkat < 10.0.0 EXEC @hr = sp_OACreate 'Chilkat.Jws', @jws2 OUT -- Load the JWS. EXEC sp_OAMethod @jws2, 'LoadJws', @success OUT, @jwsCompact DECLARE @rsaPubKey int EXEC sp_OAMethod @privKey, 'GetPublicKey', @rsaPubKey OUT EXEC @hr = sp_OADestroy @privKey -- Set the RSA public key used for validation. SELECT @signatureIndex = 0 EXEC sp_OAMethod @jws2, 'SetPublicKey', @success OUT, @signatureIndex, @rsaPubKey EXEC @hr = sp_OADestroy @rsaPubKey -- Validate the 1st (and only) signature at index 0.. DECLARE @v int EXEC sp_OAMethod @jws2, 'Validate', @v OUT, @signatureIndex IF @v < 0 BEGIN -- Perhaps Chilkat was not unlocked or the trial expired.. PRINT 'Method call failed for some other reason.' EXEC sp_OAGetProperty @jws2, 'LastErrorText', @sTmp0 OUT PRINT @sTmp0 EXEC @hr = sp_OADestroy @cert EXEC @hr = sp_OADestroy @jwsProtHdr EXEC @hr = sp_OADestroy @jws EXEC @hr = sp_OADestroy @jws2 RETURN END IF @v = 0 BEGIN PRINT 'Invalid signature. The RSA key was incorrect, the JWS was invalid, or both.' EXEC @hr = sp_OADestroy @cert EXEC @hr = sp_OADestroy @jwsProtHdr EXEC @hr = sp_OADestroy @jws EXEC @hr = sp_OADestroy @jws2 RETURN END -- If we get here, the signature was validated.. PRINT 'Signature validated.' -- Recover the original content: EXEC sp_OAMethod @jws2, 'GetPayload', @sTmp0 OUT, 'utf-8' PRINT @sTmp0 -- Examine the protected header: DECLARE @joseHeader int EXEC sp_OAMethod @jws2, 'GetProtectedHeader', @joseHeader OUT, @signatureIndex EXEC sp_OAGetProperty @jws2, 'LastMethodSuccess', @iTmp0 OUT IF @iTmp0 <> 1 BEGIN PRINT 'No protected header found at the given index.' EXEC @hr = sp_OADestroy @cert EXEC @hr = sp_OADestroy @jwsProtHdr EXEC @hr = sp_OADestroy @jws EXEC @hr = sp_OADestroy @jws2 RETURN END EXEC sp_OASetProperty @joseHeader, 'EmitCompact', 0 PRINT 'Protected (JOSE) header:' EXEC sp_OAMethod @joseHeader, 'Emit', @sTmp0 OUT PRINT @sTmp0 EXEC @hr = sp_OADestroy @joseHeader -- Output: -- Signature validated. -- In our village, folks say God crumbles up the old moon into stars. -- Protected (JOSE) header: -- { -- "alg": "RS256" -- } EXEC @hr = sp_OADestroy @cert EXEC @hr = sp_OADestroy @jwsProtHdr EXEC @hr = sp_OADestroy @jws EXEC @hr = sp_OADestroy @jws2 END GO |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.