Xbase++ Requires Chilkat v11.5.0+
Xbase++
Create JWS Using Private Key on a Smart Card
See more JSON Web Signatures (JWS) Examples
Creates and validates a JSON Web Signature (JWS) using the private key associated with a certificate on a smart card.Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oCert
LOCAL oJwsProtHdr
LOCAL oJws
LOCAL nSignatureIndex
LOCAL nBIncludeBom
LOCAL cPayloadStr
LOCAL cJwsCompact
LOCAL oJws2
LOCAL oPubKey
LOCAL v
LOCAL oJoseHeader
nSuccess := 0
// This requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Load the certificate from a smart card.
oCert := CreateObject("Chilkat.Cert")
// Set the smarcard PIN prior to loading
oCert:SmartCardPin := "123456"
// Detect the connected smartcard or USB security token and load the default certificate.
nSuccess := oCert:LoadFromSmartcard("")
IF (nSuccess == 0)
? oCert:LastErrorText
oCert:destroy()
RETURN
ENDIF
// Note: Chilkat provides many different ways to load a certificate from a smartcard or USB token,
// such as selecting a certificate if the card contains multiple certificates with private keys,
// or working with lower-level PKCS11 or ScMinidriver API's (both of which Chilkat provides).
// Create the JWS Protected Header
oJwsProtHdr := CreateObject("Chilkat.JsonObject")
IF (oCert:IsEcdsa() == 1)
oJwsProtHdr:AppendString("alg", "ES256")
ELSE
oJwsProtHdr:AppendString("alg", "RS256")
ENDIF
oJws := CreateObject("Chilkat.Jws")
// Set the protected header:
nSignatureIndex := 0
oJws:SetProtectedHeader(nSignatureIndex, oJwsProtHdr)
// Provide the private key via the certificate.
// This requires Chilkat v11.5.0 or greater.
oJws:SetSigningCert(nSignatureIndex, oCert)
// Set the payload.
nBIncludeBom := 0
cPayloadStr := "In our village, folks say God crumbles up the old moon into stars."
oJws:SetPayload(cPayloadStr, "utf-8", nBIncludeBom)
// Create the JWS
// By default, the compact serialization is used.
cJwsCompact := oJws:CreateJws()
IF (oJws:LastMethodSuccess == 0)
? oJws:LastErrorText
oCert:destroy()
oJwsProtHdr:destroy()
oJws:destroy()
RETURN
ENDIF
? "JWS: " + cJwsCompact
// sample output:
// JWS: eyJhbGciOiJQUzI1NiJ9.SW4gb3VyIHZpbGxhZ2UsIGZvbGtzIHNheSBHb2QgY3J1bWJsZXMgdXAgdGhlIG9sZCBtb29uIGludG8gc3RhcnMu.TRWhwRo5dMv9-8OzrInfJTwmUGYgjLfHk8lqF072ND-FmLWEBnUTOpY8oJXp8FdWw2SalbdOeNlrtlJjwk4XK8Ql2iJ_2qMCtxsvLPhKBOqFoAF4aBvTOEDVJDxf0DaBSiydEEtfTVV2iwBcjWabu5J2XieR5y7QZQtuHsn7T3qKBvCcCejN3Y2oqAT3qMHvu1fTms1r_91wBn_K7Wjd9UkZ1n02qQcUHJznR_OF2BgN7_KWIDAF9ZS9keoju2NPpPelO4yxa2XUPnehY3G7dHKoCxUEQR4d2Xc5voqDASTVCDqQS4PVOZdvT3Ein6-SanAlCwbWBbkvT8g6-5PImQ
// Now load the JWS, validate, and recover the original text.
oJws2 := CreateObject("Chilkat.Jws")
// Load the JWS.
nSuccess := oJws2:LoadJws(cJwsCompact)
oPubKey := CreateObject("Chilkat.PublicKey")
oCert:GetPublicKey(oPubKey)
// Set the public key used for validation.
nSignatureIndex := 0
oJws2:SetPublicKey(nSignatureIndex, oPubKey)
// Validate the 1st (and only) signature at index 0..
v := oJws2:Validate(nSignatureIndex)
IF (v < 0)
// Perhaps Chilkat was not unlocked or the trial expired..
? "Method call failed for some other reason."
? oJws2:LastErrorText
oCert:destroy()
oJwsProtHdr:destroy()
oJws:destroy()
oJws2:destroy()
oPubKey:destroy()
RETURN
ENDIF
IF (v == 0)
? "Invalid signature. The key was incorrect, the JWS was invalid, or both."
oCert:destroy()
oJwsProtHdr:destroy()
oJws:destroy()
oJws2:destroy()
oPubKey:destroy()
RETURN
ENDIF
// If we get here, the signature was validated..
? "Signature validated."
// Recover the original content:
? oJws2:GetPayload("utf-8")
// Examine the protected header:
oJoseHeader := CreateObject("Chilkat.JsonObject")
nSuccess := oJws2:GetProtectedH(nSignatureIndex, oJoseHeader)
IF (nSuccess == 0)
? oJws2:LastErrorText
oCert:destroy()
oJwsProtHdr:destroy()
oJws:destroy()
oJws2:destroy()
oPubKey:destroy()
oJoseHeader:destroy()
RETURN
ENDIF
oJoseHeader:EmitCompact := 0
? "Protected (JOSE) header:"
? oJoseHeader:Emit()
// Output:
// Signature validated.
// In our village, folks say God crumbles up the old moon into stars.
// Protected (JOSE) header:
// {
// "alg": "RS256"
// }
oCert:destroy()
oJwsProtHdr:destroy()
oJws:destroy()
oJws2:destroy()
oPubKey:destroy()
oJoseHeader:destroy()