Sample code for 30+ languages & platforms
Tcl Requires Chilkat v11.0.0+

PKCS11 Export Public Key from HSM

See more PKCS11 Examples

Demonstrates how to export a public key from a smartcard or token.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  This example requires the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

#  Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

set pkcs11 [new_CkPkcs11]

#  Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
#  (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
CkPkcs11_put_SharedLibPath $pkcs11 "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll"

#  Establish a logged-on session. (We can typically skip the login by passing an empty PIN if only working with public keys)
#  Use your actual PIN here, or an empty string to skip login.
set pin "0000"
set userType 1
set success [CkPkcs11_QuickSession $pkcs11 $userType $pin]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    exit
}

#  Get the handle of the public key we wish to export.
#  You can find public keys in many different ways.
#  This example will search for a public key by label.

#  Provide a template to find a PKCS11 object.
set jsonTemplate [new_CkJsonObject]

#  Find the public key with the label "Belgium eHealth".
CkJsonObject_UpdateString $jsonTemplate "class" "public_key"
CkJsonObject_UpdateString $jsonTemplate "label" "Belgium eHealth"

set pubKeyHandle [CkPkcs11_FindObject $pkcs11 $jsonTemplate]
if {$pubKeyHandle == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkJsonObject $jsonTemplate
    exit
}

#  Export to a Chilkat public key object.
set pubKey [new_CkPublicKey]

set success [CkPkcs11_ExportPublicKey $pkcs11 $pubKeyHandle $pubKey]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkJsonObject $jsonTemplate
    delete_CkPublicKey $pubKey
    exit
}

#  Get the public key as PKCS8 PEM.
puts [CkPublicKey_getPem $pubKey 0]

CkPkcs11_Logout $pkcs11
CkPkcs11_CloseSession $pkcs11

delete_CkPkcs11 $pkcs11
delete_CkJsonObject $jsonTemplate
delete_CkPublicKey $pubKey