Sample code for 30+ languages & platforms
SQL Server

PKCS11 Find All Certificates on Smart Card or USB Token

See more PKCS11 Examples

Sample code showing how to examine all the certificates on a smart card or USB token.

Note: This example requires Chilkat v9.5.0.88 or later.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @iTmp0 int
    -- Important: Do not use nvarchar(max).  See the warning about using nvarchar(max).
    DECLARE @sTmp0 nvarchar(4000)
    DECLARE @success int
    SELECT @success = 0

    -- This example requires the Chilkat API to have been previously unlocked.
    -- See Global Unlock Sample for sample code.

    -- Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

    DECLARE @pkcs11 int
    EXEC @hr = sp_OACreate 'Chilkat.Pkcs11', @pkcs11 OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    -- Set your shared lib path -- either a full path to the DLL, .so, or .dylib,
    -- or just the filename if the driver is in a location that can be automatically found. (Such as in C:\Windows\System32)
    EXEC sp_OASetProperty @pkcs11, 'SharedLibPath', 'aetpkss1.dll'

    EXEC sp_OAMethod @pkcs11, 'Initialize', @success OUT
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @pkcs11
        RETURN
      END

    -- Pass -1 for the slotID to open a session on the first non-empty slot.
    DECLARE @slotID int
    SELECT @slotID = -1

    -- Open a session.
    DECLARE @readWrite int
    SELECT @readWrite = 1
    EXEC sp_OAMethod @pkcs11, 'OpenSession', @success OUT, @slotID, @readWrite
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @pkcs11
        RETURN
      END

    -- Make it an authenticated session by calling Login.
    -- 
    -- If we don't authenticate, then we won't be able to see the private keys, and thus
    -- we won't know which certificates have an associated private key stored on the smart card.

    -- The smart card PIN is passed to the Login method.
    -- userType 1 indicates a "Normal User".
    DECLARE @userType int
    SELECT @userType = 1
    DECLARE @pin nvarchar(4000)
    SELECT @pin = '0000'
    EXEC sp_OAMethod @pkcs11, 'Login', @success OUT, @userType, @pin
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC sp_OAMethod @pkcs11, 'CloseSession', @success OUT
        EXEC @hr = sp_OADestroy @pkcs11
        RETURN
      END

    -- Call FindAllCerts to find all certificates on the smart card or USB token.
    EXEC sp_OAMethod @pkcs11, 'FindAllCerts', @success OUT
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC sp_OAMethod @pkcs11, 'CloseSession', @success OUT
        EXEC @hr = sp_OADestroy @pkcs11
        RETURN
      END

    -- The NumCerts property is set by FindAllCerts.
    DECLARE @numCerts int
    EXEC sp_OAGetProperty @pkcs11, 'NumCerts', @numCerts OUT

    PRINT 'Number of certs: ' + @numCerts

    DECLARE @privateKeyNote nvarchar(4000)

    DECLARE @cert int
    EXEC @hr = sp_OACreate 'Chilkat.Cert', @cert OUT

    DECLARE @i int
    SELECT @i = 0
    WHILE @i < @numCerts
      BEGIN
        EXEC sp_OAMethod @pkcs11, 'GetCert', @success OUT, @i, @cert
        SELECT @privateKeyNote = ''
        EXEC sp_OAMethod @cert, 'HasPrivateKey', @iTmp0 OUT
        IF @iTmp0 = 1
          BEGIN
            SELECT @privateKeyNote = '(has private key)'
          END


        EXEC sp_OAGetProperty @cert, 'SubjectDN', @sTmp0 OUT
        PRINT @i + ': ' + @privateKeyNote + ' ' + @sTmp0

        EXEC sp_OAGetProperty @cert, 'IssuerDN', @sTmp0 OUT
        PRINT @i + ': issuer: ' + @sTmp0

        PRINT '----'
        SELECT @i = @i + 1
      END

    -- Revert to an unauthenticated session by calling Logout.
    EXEC sp_OAMethod @pkcs11, 'Logout', @success OUT
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC sp_OAMethod @pkcs11, 'CloseSession', @success OUT
        EXEC @hr = sp_OADestroy @pkcs11
        EXEC @hr = sp_OADestroy @cert
        RETURN
      END

    -- When finished, close the session.
    -- It is important to close the session (memory leaks will occur if the session is not properly closed).
    EXEC sp_OAMethod @pkcs11, 'CloseSession', @success OUT
    IF @success = 0
      BEGIN
        EXEC sp_OAGetProperty @pkcs11, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @pkcs11
        EXEC @hr = sp_OADestroy @cert
        RETURN
      END


    PRINT 'Success.'

    EXEC @hr = sp_OADestroy @pkcs11
    EXEC @hr = sp_OADestroy @cert


END
GO