Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

PKCS11 Export Public Key from HSM

See more PKCS11 Examples

Demonstrates how to export a public key from a smartcard or token.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPkcs11
LOCAL cPin
LOCAL nUserType
LOCAL oJsonTemplate
LOCAL nPubKeyHandle
LOCAL oPubKey

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

oPkcs11 := CreateObject("Chilkat.Pkcs11")

//  Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
//  (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
oPkcs11:SharedLibPath := "C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll"

//  Establish a logged-on session. (We can typically skip the login by passing an empty PIN if only working with public keys)
//  Use your actual PIN here, or an empty string to skip login.
cPin := "0000"
nUserType := 1
nSuccess := oPkcs11:QuickSession(nUserType, cPin)
IF (nSuccess == 0)
    ? oPkcs11:LastErrorText
    oPkcs11:destroy()
    RETURN
ENDIF

//  Get the handle of the public key we wish to export.
//  You can find public keys in many different ways.
//  This example will search for a public key by label.

//  Provide a template to find a PKCS11 object.
oJsonTemplate := CreateObject("Chilkat.JsonObject")

//  Find the public key with the label "Belgium eHealth".
oJsonTemplate:UpdateString("class", "public_key")
oJsonTemplate:UpdateString("label", "Belgium eHealth")

nPubKeyHandle := oPkcs11:FindObject(oJsonTemplate)
IF (nPubKeyHandle == 0)
    ? oPkcs11:LastErrorText
    oPkcs11:destroy()
    oJsonTemplate:destroy()
    RETURN
ENDIF

//  Export to a Chilkat public key object.
oPubKey := CreateObject("Chilkat.PublicKey")
nSuccess := oPkcs11:ExportPublicKey(nPubKeyHandle, oPubKey)
IF (nSuccess == 0)
    ? oPkcs11:LastErrorText
    oPkcs11:destroy()
    oJsonTemplate:destroy()
    oPubKey:destroy()
    RETURN
ENDIF

//  Get the public key as PKCS8 PEM.
? oPubKey:GetPem(0)

oPkcs11:Logout()
oPkcs11:CloseSession()

oPkcs11:destroy()
oJsonTemplate:destroy()
oPubKey:destroy()