Sample code for 30+ languages & platforms
Tcl

PKCS11 Certificate Chain

See more PKCS11 Examples

Demonstrates how to make CA certs available for the certificate chain to be included when creating a signature (using a PKCS11 compatible smart card / USB token) such as for PDF, XMLDSig, etc.

Note: This example requires Chilkat v9.5.0.88 or later.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

set pkcs11 [new_CkPkcs11]

# You will use the DLL (or shared lib) provided by your smart card vendor, or a DLL compatible with your smart card.
# On Windows, if the DLL is located in C:\Windows\System32, specify only the filename.
# Otherwise provide the full path.
CkPkcs11_put_SharedLibPath $pkcs11 "bit4xpki.dll"

set success [CkPkcs11_Initialize $pkcs11]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    exit
}

# Pass -1 for the slotID to open a session on the first non-empty slot.
set slotID -1

# Open a session.
set readWrite 1
set success [CkPkcs11_OpenSession $pkcs11 $slotID $readWrite]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    exit
}

# Make it an authenticated session by calling Login.
set userType 1
# Make sure to use the correct PIN for your smart card..
set pin "0000"
set success [CkPkcs11_Login $pkcs11 $userType $pin]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    set success [CkPkcs11_CloseSession $pkcs11]
    delete_CkPkcs11 $pkcs11
    exit
}

# Get the certificate (on the smart card) that has a private key.
set cert [new_CkCert]

set success [CkPkcs11_FindCert $pkcs11 "privateKey" "" $cert]
if {$success == 1} then {
    puts "Cert with private key: [CkCert_subjectCN $cert]"
} else {
    puts "No certificates having a private key were found."
    set success [CkPkcs11_CloseSession $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkCert $cert
    exit
}

# If the certificates in the chain of authentication were contained on the smart card,
# then Chilkat would already have them (via the FindCert function) and the certs in the chain will be automatically used
# as needed when signing occurs.

# If you have CA certs located elsewhere, such as in .cer files, you can make them available to Chilkat in the following way:

set certVault [new_CkXmlCertVault]

# Please review the methods available in the XML certificate vault class.  Different methods exist for adding certificates
# from various sources, such as PEM, PFX, or in-memory sources..
set success [CkXmlCertVault_AddCertFile $certVault "someDir/caIntermediateCert.cer"]
# ...
set success [CkXmlCertVault_AddCertFile $certVault "someDir/caCert.cer"]
# (Your code should check the return value to make sure it succeeded.)

set success [CkCert_UseCertVault $cert $certVault]
if {$success == 0} then {
    puts [CkCert_lastErrorText $cert]
    set success [CkPkcs11_CloseSession $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkCert $cert
    delete_CkXmlCertVault $certVault
    exit
}

# --------------------------------------------------------------------------
# At this point, we have the cert (and certs in the chain of authentication) to be used for signing.
# The code for using the certificate in creating the digital signature, such as for a PDF, XML, etc., go here...

# --------------------------------------------------------------------------

# Revert to an unauthenticated session by calling Logout.
set success [CkPkcs11_Logout $pkcs11]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    set success [CkPkcs11_CloseSession $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkCert $cert
    delete_CkXmlCertVault $certVault
    exit
}

# When finished, close the session.
# It is important to close the session (memory leaks will occur if the session is not properly closed).
set success [CkPkcs11_CloseSession $pkcs11]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkCert $cert
    delete_CkXmlCertVault $certVault
    exit
}

puts "Success."

delete_CkPkcs11 $pkcs11
delete_CkCert $cert
delete_CkXmlCertVault $certVault