Sample code for 30+ languages & platforms
Zig

PKCS11 Sign PDF using Certificate and Private Key on Smart Card / USB Token

See more PKCS11 Examples

Sample code showing how to use PKCS11 to sign a PDF with a certificate and private key stored on a smart card or USB token.

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

    const pkcs11 = try chilkat.Pkcs11.init();
    defer pkcs11.deinit();

    pkcs11.setSharedLibPath("C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll");
    const pin = "0000";
    const user_type = 1;

    // Establish a PKCS11 logged-on session using the driver (.so, .dylib, or .dll) as specified in the SharedLibPath above.
    pkcs11.quickSession(user_type, pin) catch {
        std.debug.print("{s}\n", .{try pkcs11.getLastErrorText(alloc)});
        return;
    };

    // Get the certificate (on the smart card) that has a private key.
    // There are other ways to locate a certificate on the HSM.
    // This example assumes there is a single certificate w/ private key.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    if (pkcs11.findCert("privateKey", "", cert)) {
        std.debug.print("Cert with private key: {s}\n", .{try cert.getSubjectCN(alloc)});
    } else |_| {
        std.debug.print("No certificates having a private key were found.\n", .{});
        try pkcs11.closeSession();
        return;
    }

    // --------------------------------------------------------------------------
    // At this point, we have the cert to be used for signing.
    // Our PDF signing code is the same as for a cert obtained from any other source..

    const pdf = try chilkat.Pdf.init();
    defer pdf.deinit();

    // Load a PDF to be signed.
    pdf.loadFile("qa_data/pdf/hello.pdf") catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        try pkcs11.closeSession();
        return;
    };

    const json = try chilkat.JsonObject.init();
    defer json.deinit();

    json.updateInt("page", 1) catch {};
    json.updateString("appearance.y", "top") catch {};
    json.updateString("appearance.x", "left") catch {};
    json.updateString("appearance.fontScale", "10.0") catch {};
    json.updateString("signingAlgorithm", "pss") catch {};
    json.updateString("hashAlgorithm", "sha256") catch {};

    var i: i32 = 0;
    json.setI(i);
    json.updateString("appearance.text[i]", "Digitaly signed by: Xyz Widgets, Inc.") catch {};
    i = i + 1;
    json.setI(i);
    json.updateString("appearance.text[i]", "current_dt") catch {};
    i = i + 1;
    json.setI(i);
    json.updateString("appearance.text[i]", "blah blah blah") catch {};

    // The certificate is internally linked to the Pkcs11 object, which is currently in an authenticated session.
    try pdf.setSigningCert(cert);

    pdf.signPdf(json, "qa_output/out.pdf") catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        try pkcs11.closeSession();
        return;
    };

    // --------------------------------------------------------------------------

    // Revert to an unauthenticated session by calling Logout.
    pkcs11.logout() catch {
        std.debug.print("{s}\n", .{try pkcs11.getLastErrorText(alloc)});
        try pkcs11.closeSession();
        return;
    };

    // When finished, close the session.
    // It is important to close the session (memory leaks will occur if the session is not properly closed).
    pkcs11.closeSession() catch {
        std.debug.print("{s}\n", .{try pkcs11.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});
}