Sample code for 30+ languages & platforms
Tcl

Import an SSH Key to an HSM using PKCS11

See more PKCS11 Examples

Demonstrates how to import an SSH private key to an HSM (smartcard or token).

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

set pkcs11 [new_CkPkcs11]

# Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
# For example:
CkPkcs11_put_SharedLibPath $pkcs11 "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS11.dll"

# Use your HSM's PIN.
set pin "0000"

# Normal user = 1
set userType 1

# Establish a logged-on user session with the HSM.
set success [CkPkcs11_QuickSession $pkcs11 $userType $pin]
if {$success == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    exit
}

# Create a PKCS11 template for importing the SSH key.
set jsonTemplate [new_CkJsonObject]

# Indicate the key is to be stored on the token (i.e. it is not a session-only key)
CkJsonObject_UpdateBool $jsonTemplate "token" 1
# The key should have the ability to sign
CkJsonObject_UpdateBool $jsonTemplate "sign" 1

# Let's provide a few attributes to help us find the this key at a later time.
# See SSH Public-Key Authentication using an HSM

# The ID is byte data, so it should be base64 or hex.
# Specify "id" if passing base64 data, "id_hex" for hexidecimal, or "id_ascii" for directly copying the ascii bytes of the string.
# You can provide any ID of your choice.  It is optional.
CkJsonObject_UpdateString $jsonTemplate "id_hex" "0A0B0C0D01020304"

# Optionally specify a label.
CkJsonObject_UpdateString $jsonTemplate "label" "MySshKey"

# Load the SSH key to be imported to the HSM (smartcard or token)
set sshKey [new_CkSshKey]

CkSshKey_put_Password $sshKey "password_of_the_encrypted_ppk_file"
set ppkContents [CkSshKey_loadText $sshKey "c:/my_ssh_keys/someSshKey.ppk"]
set success [CkSshKey_FromPuttyPrivateKey $sshKey $ppkContents]
if {$success == 0} then {
    puts [CkSshKey_lastErrorText $sshKey]
    delete_CkPkcs11 $pkcs11
    delete_CkJsonObject $jsonTemplate
    delete_CkSshKey $sshKey
    exit
}

# Import the SSH private key onto the HSM.
# The PKCS11 handle to the imported private key is returned.
# A 0 is returned on failure.
set privKeyHandle [CkPkcs11_ImportSshKey $pkcs11 $sshKey $jsonTemplate]
if {$privKeyHandle == 0} then {
    puts [CkPkcs11_lastErrorText $pkcs11]
    delete_CkPkcs11 $pkcs11
    delete_CkJsonObject $jsonTemplate
    delete_CkSshKey $sshKey
    exit
}

# The private key handle is only valid during the PKCS11 session.
# If you wish to use the private key in another PKCS11 session,
# you'll first need to find it.  See  SSH Public-Key Authentication using a Smartcard
puts "private key handle: $privKeyHandle"

puts "Successfully imported the SSH key onto the HSM."

CkPkcs11_Logout $pkcs11
CkPkcs11_CloseSession $pkcs11

delete_CkPkcs11 $pkcs11
delete_CkJsonObject $jsonTemplate
delete_CkSshKey $sshKey