ScMinidriver PowerBuilder Reference Documentation

ScMinidriver

Current Version: 11.6.0

Chilkat.ScMinidriver

Access smart-card certificates, key containers, PINs, files, and on-card signing.

Chilkat.ScMinidriver is a smart-card integration class for applications that need card minidriver access to certificates, key containers, PIN authentication, card files, and on-card signing. It can retrieve and link smart-card certificates for use in other Chilkat signing classes, generate or import RSA and ECC keys, sign data directly, inspect card and container state, and manage selected card files and certificates.

Connect through minidriver

Use the Windows smart-card minidriver layer to access card capabilities without working directly at the APDU level.

Certificates and containers

Enumerate and inspect smart-card certificates, key containers, container indexes, key types, and related card state.

PIN authentication

Authenticate to the card with the required PIN before accessing protected private-key operations or card objects.

On-card signing

Sign data using private keys that remain on the smart card, including workflows where the private key is non-exportable.

Key generation and import

Generate or import RSA and ECC keys into supported card containers when the card policy allows it.

Use with Chilkat signing

Link a smart-card certificate to other Chilkat classes so PDF, XML, CMS/PKCS7, S/MIME, or other signing operations can use the card-backed private key.

Common pattern: Connect to the smart card, verify the card and container state, authenticate with the PIN, locate the certificate and private-key container, then either sign directly or link the certificate for use by another Chilkat signing class. Use ScMinidriver for Windows card-minidriver certificate and key-container operations; use Chilkat.SCard for direct PC/SC APDU-level work, and Chilkat.Pkcs11 for PKCS#11 token or HSM sessions.

Object Creation

oleobject loo_ScMinidriver
integer li_rc

loo_ScMinidriver = create oleobject
li_rc = loo_ScMinidriver.ConnectToNewObject("Chilkat.ScMinidriver")
if li_rc < 0 then
    destroy loo_ScMinidriver
    MessageBox("Error","Connecting to COM object failed")
    return
end if

// ... use loo_ScMinidriver ...

destroy loo_ScMinidriver

PowerBuilder uses the Chilkat ActiveX through an oleobject: declare the variable, create it, connect it to the Chilkat class with ConnectToNewObject, and destroy it when finished. A negative return code from ConnectToNewObject means the ActiveX is not registered, or the registered ActiveX does not match the bitness (32-bit or 64-bit) of the PowerBuilder target.

Objects returned by methods (such as an HttpResponse or JsonObject) are also oleobject variables and must likewise be destroyed. A method that fails to return an object returns null; test with IsNull(). In the signatures on this page, the Chilkat class name identifies which object is expected or returned; the PowerBuilder variable type is always oleobject.

To bind to a specific major version of Chilkat, append the major version number to the ProgID, such as ConnectToNewObject("Chilkat.ScMinidriver.11") for Chilkat v11.*.*.

Members typed blob exchange binary data as a Variant byte array. The PowerBuilder examples instead use the BinData-based alternatives (methods ending in Bd), which keep binary data inside Chilkat objects.

Properties

Atr
string Atr (read-only)
Introduced in version 9.5.0.87

The ATR of the card in the reader. This property is set by the AquireContext method.

top
CardName
string CardName (read-only)
Introduced in version 9.5.0.87

The name of the card in the reader. This property is set by the AquireContext method.

top
DebugLogFilePath
string DebugLogFilePath

If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.

Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.

Possible causes of hangs include:

  • A timeout property set to 0, indicating an infinite timeout.
  • A hang occurring within an event callback in the application code.
  • An internal bug in the Chilkat code causing the hang.

More Information and Examples
top
LastBinaryResult
blob LastBinaryResult (read-only)

This property is mainly used in SQL Server stored procedures to retrieve binary data from the last method call that returned binary data. It is only accessible if Chilkat.Global.KeepBinaryResult is set to 1. This feature allows for the retrieval of large varbinary results in an SQL Server environment, which has restrictions on returning large data via method calls, though temp tables can handle binary properties.

top
LastErrorHtml
string LastErrorHtml (read-only)

Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorText
string LastErrorText (read-only)

Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorXml
string LastErrorXml (read-only)

Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastMethodSuccess
long LastMethodSuccess

Indicates the success or failure of the most recent method call: 1 means success, 0 means failure. This property remains unchanged by property setters or getters. This method is present to address challenges in checking for null or Nothing returns in certain programming languages. Note: This property does not apply to methods that return integer values or to boolean-returning methods where the boolean does not indicate success or failure.

top
LastStringResult
string LastStringResult (read-only)

In SQL Server stored procedures, this property holds the string return value of the most recent method call that returns a string. It is accessible only when Chilkat.Global.KeepStringResult is set to TRUE. SQL Server has limitations on string lengths returned from methods and properties, but temp tables can be used to access large strings.

top
LastStringResultLen
long LastStringResultLen (read-only)

The length, in characters, of the string contained in the LastStringResult property.

top
MaxContainers
long MaxContainers (read-only)
Introduced in version 9.5.0.87

The maximum number of key containers available. The 1st key container is at index 0. Each key container can potentially contain one signature key, and one key exchange key.

top
RsaPaddingHash
string RsaPaddingHash
Introduced in version 9.5.0.87

If an RSA key is used for signing, this is the hash algorithm to used in conjunction with the padding scheme. It can be SHA1, SHA256, SHA384, or SHA512. The default is SHA256.

top
RsaPaddingScheme
string RsaPaddingScheme
Introduced in version 9.5.0.87

If an RSA key is used for signing, this is the padding scheme to use. It can be PKCS or PSS. The default is PSS.

top
UncommonOptions
string UncommonOptions
Introduced in version 9.5.0.87

This is a catch-all property to be used for uncommon needs. This property defaults to the empty string and should typically remain empty.

top
VerboseLogging
long VerboseLogging

If set to 1, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is 0. Verbose logging should only be used for debugging. The potentially large quantity of logged information may adversely affect peformance.

top
Version
string Version (read-only)

Version of the component/library, such as "10.1.0"

More Information and Examples
top

Methods

AcquireContext
long AcquireContext(string readerName)
Introduced in version 9.5.0.87

Initializes communication with the card inserted in the given reader. Reader names can be discovered via the SCard.ListReaders or SCard.FindSmartcards methods. If successful, the Atr and CardName properties will be set.

Returns 1 for success, 0 for failure.

top
CardDeleteFile
long CardDeleteFile(string dirName, string fileName)
Introduced in version 9.5.0.88

Deletes the file specified by dirName and fileName. dirName is the name of the directory that contains the file, or the empty string for root.

Returns 1 for success, 0 for failure.

top
DeleteCert
long DeleteCert(ChilkatCert cert, long delPrivKey)
Introduced in version 9.5.0.88

Deletes a certificate and optionally its associated private key from the smart card. If delPrivKey is 1, then the associated private key, if it exists, is also deleted.

Returns 1 for success, 0 for failure.

top
DeleteContext
long DeleteContext()
Introduced in version 9.5.0.87

This function reverses the effect of AcquireContext and severs the communication between the Base CSP/KSP and the card minidriver. The Atr and CardName properties are cleared.

Returns 1 for success, 0 for failure.

top
DeleteKeyContainer
long DeleteKeyContainer(long containerIndex)
Introduced in version 9.5.0.87

Deletes the key container at the given containerIndex. This deletes both the signature and key exchange keys that may be contained in the specified key container.

Returns 1 for success, 0 for failure.

More Information and Examples
top
EnumFiles
long EnumFiles(string dirName, ChilkatStringTable st)
Introduced in version 9.5.0.87

Get the list of files in the directory specified by dirName. Pass the empty string for the root directory. The filenames are returned in st.

Returns 1 for success, 0 for failure.

top
FindCert
long FindCert(string certPart, string partValue, ChilkatCert cert)
Introduced in version 9.5.0.87

Finds the certificate where the given certPart equals the partValue. Possible values for certPart are: subjectDN, subjectDN_withTags, subjectCN, serial, or serial:issuerCN.

The cert is loaded with the certificate if successful.

Note: If successful, the cert will be linked internally with this ScMinidriver session such that certificate can be used for signing on the smart card when used in other Chilkat classes such as XmlDSigGen, Pdf, Crypt2, Mime, MailMan, etc.

Returns 1 for success, 0 for failure.

top
GenerateKey
long GenerateKey(long containerIndex, string keySpec, string keyType, long keySize, string pinId)
Introduced in version 9.5.0.87

Generates a key to be stored in either the signature or key exchange location within a key container. Creates the key container if it does not already exist. Otherwise replaces the key in the key container.

The keySpec can be sig or kex to specify either the signature or key exchange location.

The keyType can be ecc or rsa.

For RSA keys, the keySize is the size of the key in bits, such as 1024, 2048, 4096, etc. (2048 is a typical value.) For ECC keys, the size can be 256, 384, or 521.

The pinId can be user, or 3 through 7. (It is typically user.)

Returns 1 for success, 0 for failure.

top
GetCardProperties
long GetCardProperties(ChilkatJsonObject json)
Introduced in version 9.5.0.87

Gets all card properties and returns them in json. See the example below.

Returns 1 for success, 0 for failure.

More Information and Examples
top
GetCert
long GetCert(long containerIndex, string keySpec, ChilkatCert cert)
Introduced in version 9.5.0.87

Get the certificate at the specified containerIndex and keySpec. The keySpec can be sig or kex to specify either the signature or key exchange location within the container. The containerIndex can be -1 to choose the first key container with a certificate. The keySpec can also be any to choose either sig or kex based on which is present, with preference given to sig if both are present.

The cert is loaded with the certificate if successful.

Note: If successful, the cert will be linked internally with this ScMinidriver session such that certificate can be used for signing on the smart card when used in other Chilkat classes such as XmlDSigGen, Pdf, Crypt2, Mime, MailMan, etc.

Returns 1 for success, 0 for failure.

top
GetContainerKeys
long GetContainerKeys(long containerIndex, PublicKey sigKey, PublicKey kexKey)
Introduced in version 9.5.0.87

Queries a key container to get the keys that are present. If the signature public key is present, it is returned in sigKey. If the key exchange key is present, it is returned in kexKey.

Returns 1 for success, 0 for failure.

top
GetCspContainerMap
long GetCspContainerMap(ChilkatJsonObject json)
Introduced in version 9.5.0.87

Returns the contents of the CSP container map file (cmapfile). The information is returned in the json. This gives an overview of what key containers and certificates exist in the smart card from a CSP's point of view. See the example linked below.

Returns 1 for success, 0 for failure.

top
ImportCert
long ImportCert(ChilkatCert cert, long containerIndex, string keySpec, string pinId)
Introduced in version 9.5.0.87

Imports a certificate with its private key onto the smart card. The cert must have an accessible private key, such as will be the case if the cert was loaded from a .pfx/.p12, or if the cert was loaded from a Windows certificate store where the private key exists (and can be exported from the Windows certificate store).

The containerIndex is the container index. It can range from 0 to the MaxContainers-1.

The keySpec can be sig or kex to specify either the signature or key exchange location within the container.

The pinId can be user, or 3 through 7. (It is typically user.)

Returns 1 for success, 0 for failure.

top
ImportKey
long ImportKey(long containerIndex, string keySpec, PrivateKey privKey, string pinId)
Introduced in version 9.5.0.87

Imports a key to be stored in either the signature or key exchange location within a key container. Creates the key container if it does not already exist. Otherwise replaces the specified key in the key container.

The keySpec can be sig or kex to specify either the signature or key exchange location.

The privKey is the private key to import.

The ARG5 can be user, or 3 through 7. (It is typically user.)

Returns 1 for success, 0 for failure.

top
ListCerts
long ListCerts(string certPart, ChilkatStringTable st)
Introduced in version 9.5.0.87

Lists the certs found on the smart card. The certPart indicates the information to be returned from each certificate. Possible values are: subjectDN, subjectDN_withTags, subjectCN, serial, or serial:issuerCN. The information is returned in st.

Returns 1 for success, 0 for failure.

top
PinAuthenticate
long PinAuthenticate(string pinId, string pin)
Introduced in version 9.5.0.87

Performs regular PIN authentication. The pinId can be user, admin, or 3 through 7. (It is typically user.) The pin is the alphanumeric PIN.

Returns 0 for success. If not successful, the return value indicates the number of attempts remaining before the PIN is locked. (The number of times an incorrect PIN may be presented to the card before the PIN is blocked, and requires the admin to unblock it.) If the PIN is already blocked, the return value is -1. If the method fails for some other reason, such as if a context has not yet been acquired, the return value is -2.

top
PinAuthenticateHex
long PinAuthenticateHex(string pinId, string pin)
Introduced in version 9.5.0.87

The same as PinAutheneticate, but the PIN is passed as a hex string. For example, to pass a PIN of 0x01, 0x02, 0x03, 0x04, pass 01020304.

top
PinChange
long PinChange(string pinId, string currentPin, string newPin)
Introduced in version 9.5.0.87

Changes a PIN. The pinId can be user, admin, or 3 through 7. (It is typically user.) The currentPin is the current alphanumeric PIN. The newPin is the new PIN.

Returns 0 for success. If not successful, the return value indicates the number of attempts remaining before the PIN is locked. (The number of times an incorrect PIN may be presented to the card before the PIN is blocked, and requires the admin to unblock it.) If the PIN is already blocked, the return value is -1. If the method fails for some other reason, such as if a context has not yet been acquired, the return value is -2.

top
PinDeauthenticate
long PinDeauthenticate(string pinId)
Introduced in version 9.5.0.87

Reverses a previous PIN authentication without resetting the card. The pinId can be user, admin, or 3 through 7. (It is typically user.)

Returns 1 for success, 0 for failure.

top
ReadFile
long ReadFile(string dirName, string fileName, ChilkatBinData bd)
Introduced in version 9.5.0.87

Reads the entire file specified by dirName and fileName into bd. dirName is the name of the directory that contains the file, or the empty string for root.

Returns 1 for success, 0 for failure.

top
SignData
long SignData(long containerIndex, string keySpec, string hashDataAlg, ChilkatBinData bdData, ChilkatBinData bdSignedData)
Introduced in version 9.5.0.87

Signs the data passed in bdData. The hashDataAlg can be sha1, sha256, sha384, sha512, or none. If not equal to none, then the hash of the data passed in bdData is signed.

The containerIndex specifies the key container. By specifying the key container, you are almost specifying the key. A key container can contain two keys: A signature key, and a key-exchange key. The keySpec indicates which of these two keys to use. keySpec should be set to sig or kex.

Note: The type of signature created, such as RSA or ECC, is determined by the type of key that exists in the key container (specified by containerIndex and keySpec). If it is an RSA key, additional options can be specified via the RsaPaddingScheme and RsaPaddingHash properties.

If successful, the signature is written to bdSignedData.

Returns 1 for success, 0 for failure.

top
WriteFile
long WriteFile(string dirName, string fileName, ChilkatBinData bd)
Introduced in version 9.5.0.87

Writes the entire file specified by dirName and fileName. dirName is the name of the directory that contains the file, or the empty string for root. The entire contents of bd are written to the file on the smart card.

Returns 1 for success, 0 for failure.

top