Tcl
Tcl
PKCS11 Certificate Chain
See more PKCS11 Examples
Demonstrates how to make CA certs available for the certificate chain to be included when creating a signature (using a PKCS11 compatible smart card / USB token) such as for PDF, XMLDSig, etc.Note: This example requires Chilkat v9.5.0.88 or later.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.
set pkcs11 [new_CkPkcs11]
# You will use the DLL (or shared lib) provided by your smart card vendor, or a DLL compatible with your smart card.
# On Windows, if the DLL is located in C:\Windows\System32, specify only the filename.
# Otherwise provide the full path.
CkPkcs11_put_SharedLibPath $pkcs11 "bit4xpki.dll"
set success [CkPkcs11_Initialize $pkcs11]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
exit
}
# Pass -1 for the slotID to open a session on the first non-empty slot.
set slotID -1
# Open a session.
set readWrite 1
set success [CkPkcs11_OpenSession $pkcs11 $slotID $readWrite]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
exit
}
# Make it an authenticated session by calling Login.
set userType 1
# Make sure to use the correct PIN for your smart card..
set pin "0000"
set success [CkPkcs11_Login $pkcs11 $userType $pin]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
set success [CkPkcs11_CloseSession $pkcs11]
delete_CkPkcs11 $pkcs11
exit
}
# Get the certificate (on the smart card) that has a private key.
set cert [new_CkCert]
set success [CkPkcs11_FindCert $pkcs11 "privateKey" "" $cert]
if {$success == 1} then {
puts "Cert with private key: [CkCert_subjectCN $cert]"
} else {
puts "No certificates having a private key were found."
set success [CkPkcs11_CloseSession $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkCert $cert
exit
}
# If the certificates in the chain of authentication were contained on the smart card,
# then Chilkat would already have them (via the FindCert function) and the certs in the chain will be automatically used
# as needed when signing occurs.
# If you have CA certs located elsewhere, such as in .cer files, you can make them available to Chilkat in the following way:
set certVault [new_CkXmlCertVault]
# Please review the methods available in the XML certificate vault class. Different methods exist for adding certificates
# from various sources, such as PEM, PFX, or in-memory sources..
set success [CkXmlCertVault_AddCertFile $certVault "someDir/caIntermediateCert.cer"]
# ...
set success [CkXmlCertVault_AddCertFile $certVault "someDir/caCert.cer"]
# (Your code should check the return value to make sure it succeeded.)
set success [CkCert_UseCertVault $cert $certVault]
if {$success == 0} then {
puts [CkCert_lastErrorText $cert]
set success [CkPkcs11_CloseSession $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkCert $cert
delete_CkXmlCertVault $certVault
exit
}
# --------------------------------------------------------------------------
# At this point, we have the cert (and certs in the chain of authentication) to be used for signing.
# The code for using the certificate in creating the digital signature, such as for a PDF, XML, etc., go here...
# --------------------------------------------------------------------------
# Revert to an unauthenticated session by calling Logout.
set success [CkPkcs11_Logout $pkcs11]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
set success [CkPkcs11_CloseSession $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkCert $cert
delete_CkXmlCertVault $certVault
exit
}
# When finished, close the session.
# It is important to close the session (memory leaks will occur if the session is not properly closed).
set success [CkPkcs11_CloseSession $pkcs11]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkCert $cert
delete_CkXmlCertVault $certVault
exit
}
puts "Success."
delete_CkPkcs11 $pkcs11
delete_CkCert $cert
delete_CkXmlCertVault $certVault