Tcl
Tcl
PKCS11 Find all Public Keys
See more PKCS11 Examples
Demonstrates how to list all public keys on an HSM.Note: This example requires Chilkat v9.5.0.96 or later.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.
set pkcs11 [new_CkPkcs11]
# Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
# (The format of the path will change with the operating system. Obviously, "C:/" is not used on non-Windows systems.
CkPkcs11_put_SharedLibPath $pkcs11 "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll"
# Establish a logged-on session. (We can typically skip the login by passing an empty PIN if only needing to list public keys)
# Use your actual PIN here, or an empty string to skip login.
set pin "0000"
set userType 1
set success [CkPkcs11_QuickSession $pkcs11 $userType $pin]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
exit
}
# Note: To find public keys, we need a session, but it doesn't necessarily need to be logged-on.
set json [new_CkJsonObject]
CkJsonObject_put_EmitCompact $json 0
set success [CkPkcs11_FindAllKeys $pkcs11 "public" $json]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkJsonObject $json
exit
}
puts [CkJsonObject_emit $json]
# Sample output, with parsing code below..
# {
# "keys": [
# {
# "handle": 74842125,
# "id": "0001020304",
# "key_type": "RSA",
# "label": "Chilkat Software, Inc.",
# "modulus": "twVRf6O ... Rwa1ebFY0=",
# "exponent": "AAEAAQ=="
# },
# {
# "handle": 18415630,
# "id": "010203040A0B0C0D0E0F",
# "key_type": "RSA",
# "label": "ehealth private key",
# "modulus": "qdKjhOwA1 ... A4MtX8BYgHmLw==",
# "exponent": "AAEAAQ=="
# },
# {
# "handle": 3735567,
# "id": "D531B4B8F308489DA58350596178845973A4562E",
# "key_type": "RSA",
# "label": "d531b4b8-f308-489d-a583-505961788459",
# "modulus": "r0MmXRKBP ... HAd1kUPsNyzcQ==",
# "exponent": "AAEAAQ=="
# },
# {
# "handle": 238092304,
# "id": "0A0B0C0D01020304",
# "key_type": "RSA",
# "label": "MySshKey",
# "modulus": "ykFHcfBFOq ... rfXBK/6g9t+S6UjJ1kUQ==",
# "exponent": "AAEAAQ=="
# },
# {
# "handle": 49348625,
# "id": "48656C6C6F",
# "key_type": "RSA",
# "label": "2048-bit RSA key for testing",
# "modulus": "vReVaJzXZYIOB ... kamD/8iNvhAKlKbQ==",
# "exponent": "AAEAAQ=="
# }
# ]
# }
# Use this online tool to generate parsing code from sample JSON:
# Generate Parsing Code from JSON
set i 0
set count_i [CkJsonObject_SizeOfArray $json "keys"]
while {$i < $count_i} {
CkJsonObject_put_I $json $i
set handle [CkJsonObject_IntOf $json "keys[i].handle"]
set id [CkJsonObject_stringOf $json "keys[i].id"]
set key_type [CkJsonObject_stringOf $json "keys[i].key_type"]
set label [CkJsonObject_stringOf $json "keys[i].label"]
set modulus [CkJsonObject_stringOf $json "keys[i].modulus"]
set exponent [CkJsonObject_stringOf $json "keys[i].exponent"]
set i [expr $i + 1]
}
CkPkcs11_Logout $pkcs11
CkPkcs11_CloseSession $pkcs11
delete_CkPkcs11 $pkcs11
delete_CkJsonObject $json