Tcl
Tcl
Import an SSH Key to an HSM using PKCS11
See more PKCS11 Examples
Demonstrates how to import an SSH private key to an HSM (smartcard or token).Note: This example requires Chilkat v9.5.0.96 or later.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.
set pkcs11 [new_CkPkcs11]
# Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
# For example:
CkPkcs11_put_SharedLibPath $pkcs11 "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS11.dll"
# Use your HSM's PIN.
set pin "0000"
# Normal user = 1
set userType 1
# Establish a logged-on user session with the HSM.
set success [CkPkcs11_QuickSession $pkcs11 $userType $pin]
if {$success == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
exit
}
# Create a PKCS11 template for importing the SSH key.
set jsonTemplate [new_CkJsonObject]
# Indicate the key is to be stored on the token (i.e. it is not a session-only key)
CkJsonObject_UpdateBool $jsonTemplate "token" 1
# The key should have the ability to sign
CkJsonObject_UpdateBool $jsonTemplate "sign" 1
# Let's provide a few attributes to help us find the this key at a later time.
# See SSH Public-Key Authentication using an HSM
# The ID is byte data, so it should be base64 or hex.
# Specify "id" if passing base64 data, "id_hex" for hexidecimal, or "id_ascii" for directly copying the ascii bytes of the string.
# You can provide any ID of your choice. It is optional.
CkJsonObject_UpdateString $jsonTemplate "id_hex" "0A0B0C0D01020304"
# Optionally specify a label.
CkJsonObject_UpdateString $jsonTemplate "label" "MySshKey"
# Load the SSH key to be imported to the HSM (smartcard or token)
set sshKey [new_CkSshKey]
CkSshKey_put_Password $sshKey "password_of_the_encrypted_ppk_file"
set ppkContents [CkSshKey_loadText $sshKey "c:/my_ssh_keys/someSshKey.ppk"]
set success [CkSshKey_FromPuttyPrivateKey $sshKey $ppkContents]
if {$success == 0} then {
puts [CkSshKey_lastErrorText $sshKey]
delete_CkPkcs11 $pkcs11
delete_CkJsonObject $jsonTemplate
delete_CkSshKey $sshKey
exit
}
# Import the SSH private key onto the HSM.
# The PKCS11 handle to the imported private key is returned.
# A 0 is returned on failure.
set privKeyHandle [CkPkcs11_ImportSshKey $pkcs11 $sshKey $jsonTemplate]
if {$privKeyHandle == 0} then {
puts [CkPkcs11_lastErrorText $pkcs11]
delete_CkPkcs11 $pkcs11
delete_CkJsonObject $jsonTemplate
delete_CkSshKey $sshKey
exit
}
# The private key handle is only valid during the PKCS11 session.
# If you wish to use the private key in another PKCS11 session,
# you'll first need to find it. See SSH Public-Key Authentication using a Smartcard
puts "private key handle: $privKeyHandle"
puts "Successfully imported the SSH key onto the HSM."
CkPkcs11_Logout $pkcs11
CkPkcs11_CloseSession $pkcs11
delete_CkPkcs11 $pkcs11
delete_CkJsonObject $jsonTemplate
delete_CkSshKey $sshKey